-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[FF#1678492] usefully display self-signed "TOFU"-spectrum certs #3
Comments
I'm thinking "no" for the TLS MITM gateways, tbh
I'm just rounding these all up to "eye icon with a fuchsia badge" and calling it appropriately chosen. (Third-party "Proper Root CAs", though, are another matter—at some point, I'll let the user manually review these per #2, but, in the meantime, I think CAcert is the only game in town [EDIT: seealso #20], so I've just hardcoded it in as an "alt" which gets tagged with a cyan badge.) However, for self-signed, I'd love to be able to gatekeep these and certify them, but Mozilla has blocked me on this front. |
|
Thread opened with Mozilla; fingers crossed! |
Actually, I think we'll reverse this: have a particular badge which does display to certify Mozilla-approved connections (and badge others differently, nevertheless, to prevent spoofing). This will also visually differentiate it from the badge-less "uninitialized" state. I'll have to do a bit of cross-platform testing (and maybe offer a fallback), but the fox face emoji seems to work as a perfect |
https://bugzilla.mozilla.org/show_bug.cgi?id=1549605#c25
|
we need them
consider starting out just hard-coding in all these: https://www.g2.com/products/zscaler-internet-access/competitors/alternatives until we get around to implementing #2
however—
don't put any pleasant logos representing non-Mozilla-approved certificates in the UI without a badge, ever!
The text was updated successfully, but these errors were encountered: