SSL trust not system-wide
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| ca-certificates (Ubuntu) |
Confirmed
|
Wishlist
|
Unassigned | ||
| firefox (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
| nss (Ubuntu) |
Confirmed
|
Wishlist
|
Unassigned | ||
| p11-kit (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
| sssd (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
| thunderbird (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
Bug Description
When I install a corporate CA trust root with update-
This ought to work, and does on other distributions. In p11-kit there is a module p11-kit-trust.so which can be used as a drop-in replacement for NSS's own libnssckbi.so trust root module, but which reads from the system's configured trust setup instead of the hard-coded version.
This allows us to install the corporate CAs just once, and then file a bug against any package that *doesn't* then trust them.
See https:/
| no longer affects: | network-manager-openconnect (Ubuntu) |
| Changed in ca-certificates (Ubuntu): | |
| status: | Incomplete → New |
| Changed in nss (Ubuntu): | |
| status: | Incomplete → New |
| Changed in thunderbird (Ubuntu): | |
| assignee: | Olivier Tilloy (osomon) → nobody |
| Changed in firefox (Ubuntu): | |
| assignee: | Olivier Tilloy (osomon) → nobody |
| tags: | added: server-triage-discuss |
| tags: | removed: server-triage-discuss |

It does seem that p11-kit-trust.so is working correctly. If I just make a symlink from libnssckbi.so to it, corporate trust installed by update- ca-certificates *does* work in Firefox.