Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 313561 - dev-libs/nss contains unknown root certificate authority
Summary: dev-libs/nss contains unknown root certificate authority
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Default Configs (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.mozilla.org/show_bug...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-04-06 19:19 UTC by Dror Levin (RETIRED)
Modified: 2010-06-03 13:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dror Levin (RETIRED) gentoo-dev 2010-04-06 19:19:25 UTC
This was announced on: http://groups.google.com/group/mozilla.dev.security.policy/browse_thread/thread/b6493a285ba79998/26fca75f9aeff1dc

Recommendation from upstream is to remove said CA.
Comment 1 Dror Levin (RETIRED) gentoo-dev 2010-04-07 15:32:06 UTC
Most recent comment (comment #8) on the upstream bug says:
> RSA has confirmed that they are in possession of the private key for the "RSA Security 1024 V3" root certificate. RSA agrees that this root should be removed
from NSS.
> 
> There is no recent audit for this "RSA Security 1024 V3" root certificate,
because it is no longer in use. Therefore, I will continue with the root
removal process as described in https://wiki.mozilla.org/CA:Root_Change_Process#Remove_a_Root
Comment 2 Jory A. Pratt gentoo-dev 2010-04-12 01:28:43 UTC
(In reply to comment #1)
> Most recent comment (comment #8) on the upstream bug says:
> > RSA has confirmed that they are in possession of the private key for the "RSA Security 1024 V3" root certificate. RSA agrees that this root should be removed
> from NSS.
> > 
> > There is no recent audit for this "RSA Security 1024 V3" root certificate,
> because it is no longer in use. Therefore, I will continue with the root
> removal process as described in
> https://wiki.mozilla.org/CA:Root_Change_Process#Remove_a_Root
> 

There is no security issue here at all, I do not see a point in us removing it at the distro level. Security team I advise to close invalid. Mozilla team can be readded if and when a true security issue is found for nss.
Comment 3 Dror Levin (RETIRED) gentoo-dev 2010-06-03 13:52:45 UTC
Was found to not be a security issue upstream, closing.