CAcert should not be trusted by default
Bug #1258286 reported by
Luke Faraone
This bug affects 1 person
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| ca-certificates (Debian) |
Fix Released
|
Unknown
|
|||
| ca-certificates (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
| Lucid |
Fix Released
|
Undecided
|
Unassigned | ||
| Precise |
Fix Released
|
Undecided
|
Unassigned | ||
| Quantal |
Fix Released
|
Undecided
|
Unassigned | ||
| Saucy |
Fix Released
|
Undecided
|
Unassigned | ||
| Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
| ca-certificates-java (Debian) |
Fix Released
|
Unknown
|
|||
| ca-certificates-java (Ubuntu) |
Fix Released
|
High
|
Marc Deslauriers | ||
| Lucid |
Invalid
|
Undecided
|
Unassigned | ||
| Precise |
Invalid
|
Undecided
|
Unassigned | ||
| Quantal |
Won't Fix
|
Undecided
|
Unassigned | ||
| Saucy |
Won't Fix
|
Undecided
|
Unassigned | ||
| Trusty |
Fix Released
|
High
|
Marc Deslauriers | ||
| nss (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
| Lucid |
Invalid
|
Undecided
|
Unassigned | ||
| Precise |
Fix Released
|
Undecided
|
Unassigned | ||
| Quantal |
Fix Released
|
Undecided
|
Unassigned | ||
| Saucy |
Fix Released
|
Undecided
|
Unassigned | ||
| Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
Bug Description
Ubuntu is one of the few distributions shipping CAcert as a trusted certificate. Many distributions are considering[1] whether to remove CAcert, and Mozilla closed the RFE[2] for CAcert in 2008, which was opened in 2003.
Concerns were expressed about CAcert's code quality[3], and their audit appears to be stalled.
In the past, it appears that Ubuntu disabled[4] CAcert, but this is no longer the case. It may be wise to do so again.
[1]:http://
[2]: https:/
[3]: http://
[4]: http://
Related branches
CVE References
| Changed in ca-certificates (Debian): | |
| status: | Unknown → New |
| Changed in ca-certificates (Debian): | |
| status: | New → Fix Committed |
| Changed in ca-certificates (Debian): | |
| status: | Fix Committed → Fix Released |
| Changed in ca-certificates-java (Debian): | |
| status: | Unknown → New |
| Changed in ca-certificates-java (Debian): | |
| status: | New → Fix Committed |
| Changed in ca-certificates-java (Debian): | |
| status: | Fix Committed → Fix Released |
| Changed in nss (Ubuntu Lucid): | |
| status: | New → Invalid |
| Changed in ca-certificates-java (Ubuntu Precise): | |
| status: | New → Invalid |
| Changed in ca-certificates-java (Ubuntu Lucid): | |
| status: | New → Invalid |
To post a comment you must log in.

This bug was fixed in the package ca-certificates - 20130906ubuntu2
---------------
ca-certificates (20130906ubuntu2) trusty; urgency=medium
* No longer ship cacert.org certificates. (LP: #1258286)
-- Marc Deslauriers <email address hidden> Wed, 19 Feb 2014 15:57:25 -0500