Fritz Schneider wrote:
If I got to "https://foo"; and foo has a cert for "foo.somedomain.com",
Moz doesn't complain. It looks like this is intentional

Yup, it was.


My question is: why? Seems like this is to prevent moz from
complaining in intranet environs,

bingo.


but I'm skeptical this is a Good Thing as it is...

Me too. See bugzilla bug 234058. Please feel free to add comments to that bug.

BTW, since this code is part of mozilla's crypto libraries,
a better place to have reported it would have been in n.p.m.crypto
I've redirected followups to there.

_______________________________________________
Mozilla-security mailing list
[EMAIL PROTECTED]
http://mail.mozilla.org/listinfo/mozilla-security

Reply via email to