CAcert should not be trusted by default
Bug #1258286 reported by
Luke Faraone
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ca-certificates (Debian) |
Fix Released
|
Unknown
|
|||
ca-certificates (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Lucid |
Fix Released
|
Undecided
|
Unassigned | ||
Precise |
Fix Released
|
Undecided
|
Unassigned | ||
Quantal |
Fix Released
|
Undecided
|
Unassigned | ||
Saucy |
Fix Released
|
Undecided
|
Unassigned | ||
Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
ca-certificates-java (Debian) |
Fix Released
|
Unknown
|
|||
ca-certificates-java (Ubuntu) |
Fix Released
|
High
|
Marc Deslauriers | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Precise |
Invalid
|
Undecided
|
Unassigned | ||
Quantal |
Won't Fix
|
Undecided
|
Unassigned | ||
Saucy |
Won't Fix
|
Undecided
|
Unassigned | ||
Trusty |
Fix Released
|
High
|
Marc Deslauriers | ||
nss (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Precise |
Fix Released
|
Undecided
|
Unassigned | ||
Quantal |
Fix Released
|
Undecided
|
Unassigned | ||
Saucy |
Fix Released
|
Undecided
|
Unassigned | ||
Trusty |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Ubuntu is one of the few distributions shipping CAcert as a trusted certificate. Many distributions are considering[1] whether to remove CAcert, and Mozilla closed the RFE[2] for CAcert in 2008, which was opened in 2003.
Concerns were expressed about CAcert's code quality[3], and their audit appears to be stalled.
In the past, it appears that Ubuntu disabled[4] CAcert, but this is no longer the case. It may be wise to do so again.
[1]:http://
[2]: https:/
[3]: http://
[4]: http://
Related branches
CVE References
Changed in ca-certificates (Debian): | |
status: | Unknown → New |
Changed in ca-certificates (Debian): | |
status: | New → Fix Committed |
Changed in ca-certificates (Debian): | |
status: | Fix Committed → Fix Released |
Changed in ca-certificates-java (Debian): | |
status: | Unknown → New |
Changed in ca-certificates-java (Debian): | |
status: | New → Fix Committed |
Changed in ca-certificates-java (Debian): | |
status: | Fix Committed → Fix Released |
Changed in nss (Ubuntu Lucid): | |
status: | New → Invalid |
Changed in ca-certificates-java (Ubuntu Precise): | |
status: | New → Invalid |
Changed in ca-certificates-java (Ubuntu Lucid): | |
status: | New → Invalid |
To post a comment you must log in.
This bug was fixed in the package ca-certificates - 20130906ubuntu2
---------------
ca-certificates (20130906ubuntu2) trusty; urgency=medium
* No longer ship cacert.org certificates. (LP: #1258286)
-- Marc Deslauriers <email address hidden> Wed, 19 Feb 2014 15:57:25 -0500