Root CAs exist at the discretion of browser root programs, they are not entitled to inclusion.
Conversation
Notices
-
Embed this notice
Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 29-Jun-2024 14:15:48 JST Ryan Castellucci :nonbinary_flag:
-
Embed this notice
Fabrice Roux :verified: :donor: (fabrice@infosec.exchange)'s status on Saturday, 29-Jun-2024 14:50:40 JST Fabrice Roux :verified: :donor:
@ryanc I want an extension that adds granularity in the root store.
- 1.0 trustworthy for the handful of certs that come from a “reputable” CA.
- 0.6 manually added certs.
- 0.3 certs from “fishy” CA. For example: Hong Kong post office or Comodo’s current rebranding or CAs on the brink of being booted from the browser root program.The extension should have 2 warning thresholds. There should be a modal popup in the worst case.
-
Embed this notice