5 ms·
From the article, one use case they explicitly call out is code signing verification. Parties like Apple use x509/PKI certificates for code signing. A third-pa
by cipherboy 5y ago
From the article, one use case they explicitly call out is code signing verification.
Parties like Apple use x509/PKI certificates for code signing. A third-party application COULD use this trust DB for code signing verification. If an application is signed with a (root) cert trusted by this DB, it is allowed.
Mozilla is saying woah: we only validate CA's TLS Server and S/MIME requirements (for CAs in our root DB). They don't validate that an arbitrary CA in their root DB has proper code signing certificate issuance procedures. So this theoretically application is in the wrong and they consider it a high severity vulnerability.
But I agree, there's an open question about _who_ is using the DB this way.