Michael Ströder wrote:
If e.g. a Linux distributor wants to ship Firefox and trims the list of
pre-installed trusted root CA certs is it still allowed to distribute
the resulting code as Firefox?

That's a decision for the people at the Mozilla Corporation who work with Linux distributors and others who want to distribute Firefox-branded browsers.

Note that in the past I've proposed having localized versions of Firefox have slightly different root lists, e.g. to account for national or regional CAs that have limited or no market share elsewhere in the world. As it turned out, people didn't want to do that for various reasons, but I myself am not wedded to the idea that the default root list should never be changed by downstream distributors.

Frank

--
Frank Hecker
hec...@mozillafoundation.org
_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to