SSL trust not system-wide
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ca-certificates (Ubuntu) |
Confirmed
|
Wishlist
|
Unassigned | ||
firefox (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
nss (Ubuntu) |
Confirmed
|
Wishlist
|
Unassigned | ||
p11-kit (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
sssd (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
thunderbird (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
When I install a corporate CA trust root with update-
This ought to work, and does on other distributions. In p11-kit there is a module p11-kit-trust.so which can be used as a drop-in replacement for NSS's own libnssckbi.so trust root module, but which reads from the system's configured trust setup instead of the hard-coded version.
This allows us to install the corporate CAs just once, and then file a bug against any package that *doesn't* then trust them.
See https:/
no longer affects: | network-manager-openconnect (Ubuntu) |
Changed in ca-certificates (Ubuntu): | |
status: | Incomplete → New |
Changed in nss (Ubuntu): | |
status: | Incomplete → New |
Changed in thunderbird (Ubuntu): | |
assignee: | Olivier Tilloy (osomon) → nobody |
Changed in firefox (Ubuntu): | |
assignee: | Olivier Tilloy (osomon) → nobody |
tags: | added: server-triage-discuss |
tags: | removed: server-triage-discuss |
It does seem that p11-kit-trust.so is working correctly. If I just make a symlink from libnssckbi.so to it, corporate trust installed by update- ca-certificates *does* work in Firefox.