[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-bugs] #20461 [Applications/Tor Browser]: Ship “static cache” of intermediate CAs
#20461: Ship “static cache” of intermediate CAs
------------------------------------------+----------------------
Reporter: nicoo | Owner: tbb-team
Type: enhancement | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor Browser | Version:
Severity: Normal | Keywords:
Actual Points: | Parent ID:
Points: | Reviewer:
Sponsor: |
------------------------------------------+----------------------
TBB produces certificate validation errors on incomplete certificate
chains, which may “somewhat work” on other browsers due to intermediary
CAs being present in caches.
This is problematic, as this leads users to expect certificate errors on
certain sites and simply click-through, effectively teaching them terrible
security practices.
We could ship, with TBB, a builtin list of “cached” intermediate CAs that
are prevalent among misconfigured servers. This data can be obtained from
TLS Observatory's data, according to ulfr.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20461>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs