Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 252347 - Remove Comodo root-Certificate from app-misc/ca-certificates-20080514-r2 and other
Summary: Remove Comodo root-Certificate from app-misc/ca-certificates-20080514-r2 and ...
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Default Configs (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: https://blog.startcom.org/?p=145
Whiteboard: B? [upstream]
Keywords:
: 421081 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-12-24 02:51 UTC by Lukas Barth
Modified: 2014-03-19 08:39 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lukas Barth 2008-12-24 02:51:10 UTC
Hi. As one can see in the URL I linked (<https://blog.startcom.org/?p=145>, just in case I messed it up), certificates issued by comodo resellers obviously can't be trusted, and therefore I think these certificates should be removed from ca-certificates (or at least from /etc/ca-certificates.com) and all other packages containing certificates.

Reproducible: Always

Steps to Reproduce:
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-12-25 17:44:35 UTC
The incident is discussed upstream at this Mozilla bug: https://bugzilla.mozilla.org/show_bug.cgi?id=470897
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-01-07 15:44:17 UTC
AFAICT it's maintained directly by Debian, cc'ing base-system for advice.
Comment 3 SpanKY gentoo-dev 2009-01-08 06:20:26 UTC
yes, it's maintained by debian, so i would file a bug at bugs.debian.org (if one hasnt been already)
Comment 4 SpanKY gentoo-dev 2011-03-31 01:51:41 UTC
unless i missed something, i dont think people have explicitly listed the comodo certs by serial.  we could punt all that have "comodo" in their name, but that doesnt sound like a complete solution.
Comment 5 SpanKY gentoo-dev 2012-06-14 15:29:11 UTC
*** Bug 421081 has been marked as a duplicate of this bug. ***
Comment 6 cyberbat 2012-06-14 16:15:57 UTC
I'm nearly shocked cause all comodo certs are in both firefox and chromium. So as in IE. What's happening? Why do the most popular browsers have comodo certs and most popular linux distros doesn't?
Comment 7 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 02:52:26 UTC
@base-system: any news? is there anything to do here?
Comment 8 SpanKY gentoo-dev 2013-12-22 23:30:27 UTC
no idea.  would have to check to see if debian updated things.  if not, then we haven't either.
Comment 9 SpanKY gentoo-dev 2014-03-19 08:39:35 UTC
ca-certificates is merely the mozilla's nss database in disguise.  if we're serious about getting certs removed, you should lobby mozilla.

i'd note that updating just ca-certificates won't help: nss itself still will have the certs in its own ca database, as will firefox.