Bug#699436: marked as done (iceweasel: Rogue server certificates in fresh install)

2013-01-31 Thread Daniel Kahn Gillmor
in particular, all the certs listed in http://bugs.debian.org/699436 are
known-malicious certificates; what you're seeing is a built-in preloaded
blocklist.

--dkg



signature.asc
Description: OpenPGP digital signature


Bug#699436: marked as done (iceweasel: Rogue server certificates in fresh install)

2013-01-31 Thread Daniel Kahn Gillmor
On 01/31/2013 12:07 PM, Samuel Hym wrote:
 Ok. Thank you very much for your answer, I’m relieved!
 
 Still, I find the way this is presented confusing: I had seen the trust
 setting, which says
 
 Edit certificate trust settings:
 . Trust
 * Do not trust
 
 Since this is “Edit … trust”, I was rather understanding that the current
 setting was the unselected item rather than the selected one.

Yep, i can see how that is confusing.  And it seems like displaying the
current trust settings in the table where you saw it explicitly would be
a nice additional feature. The following upstream bugs seems like it
might be relevant:

  https://bugzilla.mozilla.org/show_bug.cgi?id=733716

It might be worth following up there.

Cheers,

--dkg



signature.asc
Description: OpenPGP digital signature