Re: Removal of code signing trust bits from ca-certificates

2017-08-23 Thread Kai Engert
There hasn't been any negative feedback, neither in Rawhide, nor from updates testing. I've just pushed the update to stable F25 and F26. Kai On Tue, 2017-07-18 at 22:11 +0200, Kai Engert wrote: > Until recently, Mozilla maintained three individual trust bits for each root > CA > certificate: >

Re: Removal of code signing trust bits from ca-certificates

2017-07-19 Thread Dominik 'Rathann' Mierzejewski
On Tuesday, 18 July 2017 at 22:11, Kai Engert wrote: [...] > This update of the CA list is supposed to get published with Firefox 56 on > September 26. > > In order to allow the Fedora community to test potential effects of this > change, > I intend to publish an update to the ca-certificates pac

Removal of code signing trust bits from ca-certificates

2017-07-18 Thread Kai Engert
Until recently, Mozilla maintained three individual trust bits for each root CA certificate: - trust for TLS servers - trust for email security - trust for code signing The next CA update from Mozilla will switch the code signing trust bit OFF for all CAs. Mozilla will no longer maintain this tru