Live data from Hacker News

Let's Encrypt root certificate trusted by Mozilla

bugzilla.mozilla.org

1–10 of 166 posts

Re: Let's Encrypt root certificate trusted by Mozilla

#2
Just to be clear, this is important because eventually Let's Encrypt wants to no longer have to cross-sign their certificates for them to be considered valid.

For that to happen they have to be added as a trusted CA in most major platforms (and Firefox which has their own CA store for some reason).

Re: Let's Encrypt root certificate trusted by Mozilla

#3

Just to be clear, this is important because eventually Let's Encrypt wants to no longer have to cross-sign their certificates for them to be considered valid. For that to happen they have to be added as a trusted CA in most major platforms (and Firefox which has their own CA store for some reason).

Would be interesting if there's a roadmap for who's left to be added to.

I saw their aim is to migrate to their own root CA by the end of the year, but i wonder if this is realistically feasible?

Re: Let's Encrypt root certificate trusted by Mozilla

#6
post #4

Have any other browsers announced their intent to do the same?

Other browsers do not have their own certificate stores but use those provided by the OS. Next interesting things are whether Windows and Mac OS X add the root certificate. I think Linux distributions tend to follow Mozilla's trust.

Re: Let's Encrypt root certificate trusted by Mozilla

#8
post #4

Have any other browsers announced their intent to do the same?

Other browsers do not have their own certificate stores but use those provided by the OS. Next interesting things are whether Windows and Mac OS X add the root certificate. I think Linux distributions tend to follow Mozilla's trust.

Since Google is already cracking down on OEMs modifying the Android root store for various countries, I think it would make sense for Chrome to have the same root store as Android does (especially in light of Lenovo's Superfish, Dell's eDellroot and so on).

Re: Let's Encrypt root certificate trusted by Mozilla

#9
post #4

Have any other browsers announced their intent to do the same?

Other browsers do not have their own certificate stores but use those provided by the OS. Next interesting things are whether Windows and Mac OS X add the root certificate. I think Linux distributions tend to follow Mozilla's trust.

RE: Linux, You're correct, they're provided through the ca-certificates package[0]:

"It includes, among others, certificate authorities used by the Debian infrastructure and those shipped with Mozilla's browsers. "

RE: OSX - If you can get into Mozilla's trust stores, it's the same steps (and pro forma, more or less) [1]

[0] https://packages.debian.org/wheezy/ca-certificates

[1] https://www.apple.com/certificateauthority/ca_program.html

Post reply on HN