Join the Mozilla’s Test Days event from 9–15 Jan to test the new Firefox address bar on Firefox Beta 135 and get a chance to win Mozilla swag vouchers! 🎁

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

What do actively distrusted certificates look like in the certificate manager?

  • 4 个回答
  • 1 人有此问题
  • 6 次查看
  • 最后回复者为 cor-el

more options

In the "Servers" tab, I see a bunch of certificates, including my certificate exceptions, as well as certificates from CNNIC and DigiNotar. From what I've found on the web, these CNNIC and DigiNotar certificates have been actively distrusted by Mozilla. Do such actively distrusted certificates appear in the certificate manager? If so, what do they look like in the UI? If my browser is actively distrusting these certificates, the UI isn't making this immediately obvious.

Thanks!

In the "Servers" tab, I see a bunch of certificates, including my certificate exceptions, as well as certificates from CNNIC and DigiNotar. From what I've found on the web, these CNNIC and DigiNotar certificates have been actively distrusted by Mozilla. Do such actively distrusted certificates appear in the certificate manager? If so, what do they look like in the UI? If my browser is actively distrusting these certificates, the UI isn't making this immediately obvious. Thanks!

所有回复 (4)

more options

Hello!

The only "safe" certificate should be CNNIC. Diginotar was removed from Firefox if you would like to read about it please take a look at this link: https://blog.mozilla.org/security/2011/09/02/diginotar-removal-follow-up/ This was removed in 2011 so it has been quite a long time. Be sure to remove Diginotar however CNNIC is safe.

more options

The CNNIC certificate I am seeing is one for MCSHOLDING, an intermediate CA that has been actively distrusted: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.18.1_release_notes#Notable_Changes_in_NSS_3.18.1

Thanks for the response, but I'm still wondering what distrusted certificates look like in the certificate manager UI, if they show up at all.

由liujed于修改

more options

Hello again!


I have the certificate personally. However if you feel this is a security concern or even a privacy concern. You can always "Delete or distrust" the certificate.

more options

If you or Mozilla disables built-in root certificates then their trust bits are removed, so they can no longer be used as a trusted root certificate. Such certificates are present as a permanent exception in the Servers tab.