Comment 27 for bug 376484

Revision history for this message
In , Nelson-bolyard (nelson-bolyard) wrote :

As far as I am concerned, host names in certs must always be FQDNs.
I don't know of ANY CA that will issue certs with non-FQDN host names,
e.g. for "webmail". If no CA issues them, then any certs with such names
in them must be ones that require the user to explicitly trust them.
I have no problem with saying that users must use FF3's new ability to
permanently remember error overrides for certs with mismatched host names
if they want to associate certs with non-FQDN host names.