fraudulent DigiNotar certificate issuance
Bug Description
USN Information: This is being tracked in USN-1197-*
NOTE: The Firefox update causes a regression for certain Dutch sites which is being tracked in Bug #838322.
NOTE #2: The current update for Thunderbird still shows the DigiNotar Root CA as trusted in the certificate manager. This is due to Thunderbird using the system version of NSS. In this initial update, Thunderbird will actively distrust any certificate signed by the DigiNotar Root CA. Future updates will properly show the root CA as distrusted in the certificate manager.
WORKAROUND (from blog post):
http://
-------
http://
Qt 4.7 blog post: http://
Related branches
visibility: | private → public |
Changed in firefox (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in firefox (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in firefox (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in thunderbird (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in thunderbird (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in thunderbird (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in firefox (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in firefox (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in firefox (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in thunderbird (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in thunderbird (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in thunderbird (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in firefox (Ubuntu Maverick): | |
status: | New → In Progress |
Changed in firefox (Ubuntu Natty): | |
status: | New → In Progress |
Changed in firefox (Ubuntu Oneiric): | |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Maverick): | |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Natty): | |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Oneiric): | |
status: | New → In Progress |
Changed in firefox (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Oneiric): | |
assignee: | Micah Gersten (micahg) → Chris Coulson (chrisccoulson) |
Changed in firefox (Ubuntu Oneiric): | |
assignee: | Micah Gersten (micahg) → Chris Coulson (chrisccoulson) |
description: | updated |
Launchpad Janitor (janitor) wrote : | #1 |
Changed in firefox (Ubuntu Oneiric): | |
status: | In Progress → Fix Released |
Micah Gersten (micahg) wrote : | #2 |
Marking natty triaged since xulrunner is no longer part of the default install in natty.
Changed in xulrunner-1.9.2 (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in xulrunner-1.9.2 (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in xulrunner-1.9.2 (Ubuntu Natty): | |
importance: | Undecided → Medium |
status: | New → Triaged |
Micah Gersten (micahg) wrote : | #3 |
Oneiric is invalid as xulrunner is no longer in the distro
Changed in xulrunner-1.9.2 (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
status: | New → Invalid |
Launchpad Janitor (janitor) wrote : | #4 |
This bug was fixed in the package firefox - 3.6.21+
---------------
firefox (3.6.21+
* New upstream release v3.6.21 (FIREFOX_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Tue, 30 Aug 2011 13:56:17 -0500
Changed in firefox (Ubuntu Lucid): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #5 |
This bug was fixed in the package xulrunner-1.9.2 - 1.9.2.21+
---------------
xulrunner-1.9.2 (1.9.2.
* New upstream release v1.9.2.21 (FIREFOX_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Wed, 31 Aug 2011 00:37:50 -0500
Changed in xulrunner-1.9.2 (Ubuntu Lucid): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #6 |
This bug was fixed in the package firefox - 3.6.21+
---------------
firefox (3.6.21+
* New upstream release v3.6.21 (FIREFOX_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Tue, 30 Aug 2011 13:59:36 -0500
Changed in firefox (Ubuntu Maverick): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #7 |
This bug was fixed in the package xulrunner-1.9.2 - 1.9.2.21+
---------------
xulrunner-1.9.2 (1.9.2.
* New upstream release v1.9.2.21 (FIREFOX_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Wed, 31 Aug 2011 00:38:08 -0500
Changed in xulrunner-1.9.2 (Ubuntu Maverick): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #8 |
This bug was fixed in the package firefox - 6.0.1+build1+
---------------
firefox (6.0.1+
* New upstream stable release (FIREFOX_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Tue, 30 Aug 2011 13:56:51 -0500
Changed in firefox (Ubuntu Natty): | |
status: | In Progress → Fix Released |
summary: |
- Fraudulent *.google.com Certificate + fraudulent DigiNotar certificate issuance |
Changed in ca-certificates (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in ca-certificates (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Anonymous (sjklfjalkfsakl) wrote : | #9 |
Also affects SeaMonkey (https:/
Anonymous (sjklfjalkfsakl) wrote : | #10 |
As you might have seen at Mozilla's Bugzilla (https:/
Olivier Mengué (dolmen) wrote : | #11 |
The proposed workaround is only for Firefox.
What about other applications that may access Google services on a Ubuntu system?
Can we simply "sudo rm /etc/ssl/
Laurent Bigonville (bigon) wrote : | #12 |
debian has released ca-certificates version 20110502+nmu1 that fix this
Changed in ca-certificates (Debian): | |
status: | Unknown → Fix Released |
Micah Gersten (micahg) wrote : | #13 |
@Olivier Mengué
I am working on updates for NSS and ca-certificates to address this system wide.
@Anonymous
Seamonkey is currently not in a good state, but I will try to get an update for it eventually. In the mean time, the NSS update should take care of this security issue for most use cases.
description: | updated |
Jamie Strandboge (jdstrand) wrote : | #14 |
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
2011-09-01 15:47:52 INFO - <ca-certificate
2011-09-01 15:47:52 INFO - <ca-certificate
I: ca-certificates [main] -> ca-certificates
Changed in ca-certificates (Ubuntu Oneiric): | |
status: | New → Fix Released |
Jamie Strandboge (jdstrand) wrote : | #15 |
2011-09-01 15:48:25 INFO - <ca-certificate
2011-09-01 15:48:25 INFO - <ca-certificate
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
I: ca-certificates [main] -> ca-certificates
Changed in nss (Ubuntu Oneiric): | |
status: | New → Fix Released |
Jamie Strandboge (jdstrand) wrote : | #16 |
2011-09-01 15:48:59 INFO - <ca-certificate
2011-09-01 15:48:59 INFO - <ca-certificate
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
I: ca-certificates [main] -> ca-certificates
Changed in qt4-x11 (Ubuntu Oneiric): | |
status: | New → Fix Released |
Jamie Strandboge (jdstrand) wrote : | #17 |
2011-09-01 15:49:34 INFO - <ca-certificate
2011-09-01 15:49:34 INFO - <ca-certificate
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
I: ca-certificates [main] -> ca-certificates
Changed in thunderbird (Ubuntu Oneiric): | |
status: | In Progress → Fix Released |
status: | Fix Released → In Progress |
Changed in qt4-x11 (Ubuntu Oneiric): | |
status: | Fix Released → New |
Changed in nss (Ubuntu Oneiric): | |
status: | Fix Released → New |
Changed in ca-certificates (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in qt4-x11 (Ubuntu Maverick): | |
status: | New → Invalid |
Changed in qt4-x11 (Ubuntu Natty): | |
status: | New → Invalid |
Changed in qt4-x11 (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in ca-certificates (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in ca-certificates (Ubuntu Oneiric): | |
assignee: | nobody → Jamie Strandboge (jdstrand) |
Changed in qt4-x11 (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Maverick): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Oneiric): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Lucid): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in qt4-x11 (Ubuntu Lucid): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Oneiric): | |
assignee: | Micah Gersten (micahg) → nobody |
Changed in ca-certificates (Ubuntu Lucid): | |
status: | In Progress → Fix Committed |
Changed in ca-certificates (Ubuntu Maverick): | |
status: | In Progress → Fix Committed |
Changed in ca-certificates (Ubuntu Natty): | |
status: | In Progress → Fix Committed |
Changed in nss (Ubuntu Lucid): | |
status: | Confirmed → In Progress |
Changed in nss (Ubuntu Maverick): | |
status: | Confirmed → In Progress |
Changed in nss (Ubuntu Natty): | |
status: | Confirmed → In Progress |
Changed in seamonkey (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in seamonkey (Ubuntu Maverick): | |
status: | New → Confirmed |
Changed in seamonkey (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in seamonkey (Ubuntu Oneiric): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu Maverick): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu): | |
status: | New → Confirmed |
Micah Gersten (micahg) wrote : | #18 |
UPDATE:
Unfortunately, the ca-certificates and NSS fixes available at the moment are only a partial fix that won't actually help very much. I'm currently waiting on fixes that should address this issue completely. I will be releasing Thunderbird in a few hours with the same fix that Firefox got which blocks the rogue certificates, but possibly causes a regression for certain Dutch sites (see Description of this bug).
Launchpad Janitor (janitor) wrote : | #19 |
This bug was fixed in the package thunderbird - 3.1.13+
---------------
thunderbird (3.1.13+
* New upstream release v3.1.13 (THUNDERBIRD_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Wed, 31 Aug 2011 00:42:12 -0500
Changed in thunderbird (Ubuntu Maverick): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #20 |
This bug was fixed in the package thunderbird - 3.1.13+
---------------
thunderbird (3.1.13+
* New upstream release v3.1.13 (THUNDERBIRD_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Wed, 31 Aug 2011 00:43:28 -0500
Changed in thunderbird (Ubuntu Natty): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #21 |
This bug was fixed in the package thunderbird - 3.1.13+
---------------
thunderbird (3.1.13+
* New upstream release v3.1.13 (THUNDERBIRD_
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <email address hidden> Wed, 31 Aug 2011 00:30:47 -0500
Changed in thunderbird (Ubuntu Lucid): | |
status: | In Progress → Fix Released |
description: | updated |
Peter Hartmann (peter-hartmann-m) wrote : | #22 |
regarding the Qt bundle: I cannot find the DigiNotar root cert in there, the bundle is really old apparently.
(did:
cd src/network/ssl
csplit -s qt-ca-bundle.crt '/^$/' {*}
for i in $(ls ./xx*); do echo $i; openssl x509 -text -noout -in $i; done|grep -i 'subject:'|grep -i diginotar
... does not yield anything).
Launchpad Janitor (janitor) wrote : | #23 |
This bug was fixed in the package thunderbird - 7.0~b2+
---------------
thunderbird (7.0~b2+
* New upstream release from the beta channel (THUNDERBIRD_
- LP: #837557 and LP: #838322
* Update globalmenu-
- Only update a menu in realtime if it's parent is opening. For all other
times, just invalidate the menu. Avoids spamming dbus everytime
something changes in the menu
- When removing a menuitem from its parent, check that the index is
in-bounds. Should fix a frequent crash on startup, although it doesn't
explain how it gets in to that state in the first place
- Add the ability to turn on debugging without building Firefox with
debugging on
* Add upstream patch to only add ENABLE_JIT=1 to CXXFLAGS if any of trace/
method/yarr jit is enabled. Fixes a build failure on PPC
- add debian/
- update debian/
* Add upstream patch to fix build failure with ENABLE_YARR_JIT=0
- add debian/
- update debian/
* Add upstream patch to work around a linker bug
- add debian/
- update debian/
* Don't pass an empty --mozilla-repo= argument to client.py when creating
the source tarball without a local cache, as it totally breaks. This is
why we've got rid of all this in nightly and aurora, so we can avoid
such bandaids in the first place
- update debian/
* Messagingmenu fixes:
- Use the libunity5 ABI (LP: #839154)
- Don't use QueryInterface on objects where we can't guarantee they
implement a particular interface (LP: #826447)
* Make sure that thunderbird-
- update debian/rules
* Update eds extension to r84 from 0.3 branch
- fixes a shutdown crash
* Use the latest eds libs for the contacts integration
-- Chris Coulson <email address hidden> Tue, 06 Sep 2011 00:19:41 +0100
Changed in thunderbird (Ubuntu Oneiric): | |
status: | In Progress → Fix Released |
Micah Gersten (micahg) wrote : | #24 |
Just found out Qt 4.7 has a blacklist patch, so reopening tasks fro maverick/
Changed in qt4-x11 (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | Invalid → In Progress |
Changed in qt4-x11 (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | Invalid → In Progress |
Changed in qt4-x11 (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
status: | Invalid → Triaged |
description: | updated |
description: | updated |
Micah Gersten (micahg) wrote : | #25 |
Didier,
I was told you're doing a qt4-x11 upload, can you include the blacklist patch from the blog post in the Description of this bug?
Changed in qt4-x11 (Ubuntu Oneiric): | |
assignee: | nobody → Didier Roche (didrocks) |
yamo (stephane-gregoire) wrote : | #26 |
Hi,
For the very old Seamonkey 2.0 : http://
Launchpad Janitor (janitor) wrote : | #27 |
This bug was fixed in the package nss - 3.12.9+
---------------
nss (3.12.9+
* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/
Remove DigiNotar Root CA.
-- Micah Gersten <email address hidden> Wed, 07 Sep 2011 14:53:13 -0500
Changed in nss (Ubuntu Lucid): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #28 |
This bug was fixed in the package nss - 3.12.9+
---------------
nss (3.12.9+
* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/
Remove DigiNotar Root CA.
-- Micah Gersten <email address hidden> Wed, 07 Sep 2011 14:55:24 -0500
Changed in nss (Ubuntu Maverick): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #29 |
This bug was fixed in the package nss - 3.12.9+
---------------
nss (3.12.9+
* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/
Remove DigiNotar Root CA.
-- Micah Gersten <email address hidden> Wed, 07 Sep 2011 15:15:37 -0500
Changed in nss (Ubuntu Natty): | |
status: | In Progress → Fix Released |
Launchpad Janitor (janitor) wrote : | #30 |
This bug was fixed in the package ca-certificates - 20090814ubuntu0
---------------
ca-certificates (20090814ubuntu
* SECURITY UPDATE: Blacklist "DigiNotar Root CA" due to fraudulent
certificate issuance (LP: #837557)
- update mozilla/
-- Micah Gersten <email address hidden> Thu, 01 Sep 2011 11:38:01 -0500
Changed in ca-certificates (Ubuntu Lucid): | |
status: | Fix Committed → Fix Released |
Launchpad Janitor (janitor) wrote : | #31 |
This bug was fixed in the package ca-certificates - 20090814ubuntu0
---------------
ca-certificates (20090814ubuntu
* SECURITY UPDATE: Blacklist "DigiNotar Root CA" due to fraudulent
certificate issuance (LP: #837557)
- update mozilla/
-- Micah Gersten <email address hidden> Thu, 01 Sep 2011 11:42:30 -0500
Changed in ca-certificates (Ubuntu Maverick): | |
status: | Fix Committed → Fix Released |
Launchpad Janitor (janitor) wrote : | #32 |
This bug was fixed in the package ca-certificates - 20090814+
---------------
ca-certificates (20090814+
* SECURITY UPDATE: Blacklist "DigiNotar Root CA" due to fraudulent
certificate issuance (LP: #837557)
- update mozilla/
-- Micah Gersten <email address hidden> Thu, 01 Sep 2011 11:53:21 -0500
Changed in ca-certificates (Ubuntu Natty): | |
status: | Fix Committed → Fix Released |
Launchpad Janitor (janitor) wrote : | #33 |
This bug was fixed in the package qt4-x11 - 4:4.7.4-0ubuntu1
---------------
qt4-x11 (4:4.7.4-0ubuntu1) oneiric; urgency=low
* New upstream release (LP: #839557, #785318)
* debian/
debian/
debian/
debian/
debian/
- adapt to new upstream version
* Fix_GL_
Fixed_
Prevent_
kubuntu_
kubuntu_
- removed, part of the upstream tarball now
* debian/
- updated to take a version closer to the upstreamed 4.8 one. Is compatible
with incoming appmenu-qt 0.2.2 (LP: #838115)
* debian/
- libtcpserver.so has been renamed libqmldbg_tcp.so
* debian/control, debian/
- add the new shaders package. Use the same suggests/recommends pattern
than other declarative-* plugins
* debian/
- add DigiNotar securty breach blacklist (LP: #837557)
-- Didier Roche <email address hidden> Thu, 08 Sep 2011 11:33:52 +0200
Changed in qt4-x11 (Ubuntu Oneiric): | |
status: | Triaged → Fix Released |
Launchpad Janitor (janitor) wrote : | #34 |
This bug was fixed in the package nss - 3.12.9+
---------------
nss (3.12.9+
* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/
Remove DigiNotar Root CA.
* Add a symlink from Linux2.6.mk to Linux3.0.mk; This is a temporary hack to
let NSS build on a 3.0.x kernel
- update debian/rules
-- Micah Gersten <email address hidden> Fri, 09 Sep 2011 11:57:13 -0500
Changed in nss (Ubuntu Oneiric): | |
status: | Confirmed → Fix Released |
Micah Gersten (micahg) wrote : | #35 |
Lucid, Maverick, and Natty builds of qt4-x11 will be available in ubuntu-
Changed in nss (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in qt4-x11 (Ubuntu Maverick): | |
status: | In Progress → Fix Committed |
Micah Gersten (micahg) wrote : | #36 |
While Lucid doesn't have the DigiNotar root CA, we can still blacklist like we did for Comodo.
Changed in qt4-x11 (Ubuntu Natty): | |
status: | In Progress → Fix Committed |
Changed in qt4-x11 (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
status: | Confirmed → Fix Committed |
Changed in ca-certificates (Debian): | |
importance: | Unknown → Undecided |
status: | Fix Released → New |
Micah Gersten (micahg) wrote : | #37 |
Please don't change bug watches without a comment.
Changed in ca-certificates (Debian): | |
importance: | Undecided → Unknown |
status: | New → Unknown |
Changed in ca-certificates (Debian): | |
status: | Unknown → Fix Released |
Launchpad Janitor (janitor) wrote : | #38 |
This bug was fixed in the package qt4-x11 - 4:4.6.2-0ubuntu5.3
---------------
qt4-x11 (4:4.6.
* SECURITY UPDATE: Blacklist Diginotar root and intermediate certificates;
Fraudulent certificates were mis-issued that could allow an attacker to
monitor secure communication through a man-in-the-middle (MITM) attack
- add debian/
- LP: #837557
-- Micah Gersten <email address hidden> Fri, 09 Sep 2011 18:36:48 -0500
Changed in qt4-x11 (Ubuntu Lucid): | |
status: | Fix Committed → Fix Released |
Launchpad Janitor (janitor) wrote : | #39 |
This bug was fixed in the package qt4-x11 - 4:4.7.0-0ubuntu4.4
---------------
qt4-x11 (4:4.7.
* SECURITY UPDATE: Blacklist Diginotar root and intermediate certificates;
Fraudulent certificates were mis-issued that could allow an attacker to
monitor secure communication through a man-in-the-middle (MITM) attack
- add debian/
- LP: #837557
-- Micah Gersten <email address hidden> Fri, 09 Sep 2011 15:43:49 -0500
Changed in qt4-x11 (Ubuntu Maverick): | |
status: | Fix Committed → Fix Released |
Launchpad Janitor (janitor) wrote : | #40 |
This bug was fixed in the package qt4-x11 - 4:4.7.2-0ubuntu6.3
---------------
qt4-x11 (4:4.7.
* SECURITY UPDATE: Blacklist Diginotar root and intermediate certificates;
Fraudulent certificates were mis-issued that could allow an attacker to
monitor secure communication through a man-in-the-middle (MITM) attack
- add debian/
- LP: #837557
-- Micah Gersten <email address hidden> Fri, 09 Sep 2011 18:27:52 -0500
Changed in qt4-x11 (Ubuntu Natty): | |
status: | Fix Committed → Fix Released |
Dmitry Shachnev (mitya57) wrote : | #41 |
Fixed with the recent update to Chromium 14.
Changed in chromium-browser (Ubuntu Oneiric): | |
status: | Confirmed → Fix Released |
Changed in chromium-browser (Ubuntu Lucid): | |
status: | Confirmed → Fix Committed |
Changed in chromium-browser (Ubuntu Maverick): | |
status: | Confirmed → Fix Committed |
Changed in chromium-browser (Ubuntu Natty): | |
status: | Confirmed → Fix Committed |
Micah Gersten (micahg) wrote : | #42 |
Fixed in 14.0.835.
Changed in chromium-browser (Ubuntu Lucid): | |
status: | Fix Committed → Fix Released |
Micah Gersten (micahg) wrote : | #43 |
Fixed in 14.0.835.
Changed in chromium-browser (Ubuntu Maverick): | |
status: | Fix Committed → Fix Released |
Micah Gersten (micahg) wrote : | #44 |
Fixed in 14.0.835.
Changed in chromium-browser (Ubuntu Natty): | |
status: | Fix Committed → Fix Released |
Launchpad Janitor (janitor) wrote : | #45 |
This bug was fixed in the package xulrunner-1.9.2 - 1.9.2.27+
---------------
xulrunner-1.9.2 (1.9.2.
* SECURITY UPDATE: New upstream release v1.9.2.27 (FIREFOX_
See the following for more information:
- LP: #934073
- USN-1353-1
- USN-1251-1
- USN-1210-1
- LP: #838322
- LP: #837557
- USN-1184-1
- USN-1149-1
-- Jamie Strandboge <email address hidden> Fri, 17 Feb 2012 08:04:19 -0600
Changed in xulrunner-1.9.2 (Ubuntu Natty): | |
status: | Triaged → Fix Released |
Jamie Strandboge (jdstrand) wrote : | #46 |
Thank you for reporting this bug to Ubuntu. maverick has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against maverick is being marked "Won't Fix". Please see
https:/
releases.
Please feel free to report any other bugs you may find.
Changed in seamonkey (Ubuntu Maverick): | |
status: | Confirmed → Won't Fix |
Jamie Strandboge (jdstrand) wrote : | #47 |
Thank you for reporting this bug to Ubuntu. natty has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against natty is being marked "Won't Fix". Please see
https:/
releases.
Please feel free to report any other bugs you may find.
Changed in seamonkey (Ubuntu Natty): | |
status: | Confirmed → Won't Fix |
Jamie Strandboge (jdstrand) wrote : | #48 |
Thank you for reporting this bug to Ubuntu. oneiric has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against oneiric is being marked "Won't Fix". Please see
https:/
releases.
Please feel free to report any other bugs you may find.
Changed in seamonkey (Ubuntu Oneiric): | |
status: | Confirmed → Won't Fix |
Changed in seamonkey (Ubuntu Lucid): | |
status: | Confirmed → Won't Fix |
Changed in ca-certificates (Ubuntu): | |
assignee: | Jamie Strandboge (jdstrand) → nobody |
Nora Blob (no-rabe) wrote : | #49 |
Hello I observed this issue in:
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 17.10
Release: 17.10
Codename: artful
I also observed it in a local build from the gentoo repositories. I attached the certs and will open issues at gentoo and mozilla.
Nora Blob (no-rabe) wrote : | #50 |
Nora Blob (no-rabe) wrote : | #51 |
Olivier Tilloy (osomon) wrote : | #52 |
Nora Blob, Ubuntu 17.10 is EOL and not supported any longer. Is the issue present in a supported release of Ubuntu (14.04, 16.04, 18.04, 18.10) or in the current development version (19.04) ?
Nora Blob (no-rabe) wrote : | #53 |
Hello Oliver Tilloy,
I can reproduce this issue in
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 18.04.1 LTS
Release: 18.04
Codename: bionic
I created a new profile with firefox -p --new-instance, and get the certificates in the new profile with the new instance. If I delete the certificates they will be in the certificate manager with every new profile.
Nora Blob (no-rabe) wrote : | #54 |
Hello Oliver Tilloy,
can you verify this issue?
Best regrads
Olivier Tilloy (osomon) wrote : | #55 |
Nora Blob: those are blacklist entries. See details at https:/
This bug was fixed in the package firefox - 7.0~b3+ build1+ nobinonly- 0ubuntu1
--------------- build1+ nobinonly- 0ubuntu1) oneiric; urgency=low
firefox (7.0~b3+
* New upstream release from the beta channel (FIREFOX_ 7_0b3_BUILD1)
- LP: #837557
-- Chris Coulson <email address hidden> Tue, 30 Aug 2011 19:15:51 +0100