Scripts should also have a way to output the NSS trust values, or an
appropriate mapping thereof for So users of the output of these scripts
can see them...
At some point the users of these cert trust values will need to find
some way to encode explicitly revoked certs as well. That is starting to
get far afield from the original issue, so I think it's more of a 'throw
away' communication to them. Not really a solution to the bug.
bob
> Wan-Teh Chang
> After the two CA break-in incidents this year, certdata.txt started to
> contain several explicitly distrusted certificates. Scripts that
> extract trusted root CA certificates from certdata.txt must now check
> the trust objects.
>
> Here are the instructions.
I'd say it's going to be difficult for the typical scripting language to do
the recommended instructions. How about putting the distrusted certs and
their trust objects in a separate file in the CVS repository?
What particularly do you think is difficult about it?
Gerv
The MD5 collision cert was there even before those events.
Here's the script I use for openSUSE. It optionally exports the trust
settings too:
http://gitorious.org/opensuse/ca-certificates/blobs/master/extractcerts.pl
For processing outside NSS it would be easier if the certificates
were available as individual pem files in the first place of course :-)
cu
Ludwig
--
(o_ Ludwig Nussel
//\
V_/_ http://www.suse.de/
SUSE LINUX Products GmbH, GF: Jeff Hawn, Jennifer Guild, Felix Imend�rffer, HRB 16746 (AG N�rnberg)