[Bug 310999]

2021-05-21 Thread Sakhtemooon24
.ir/)? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug

[Bug 310999]

2021-05-21 Thread Gijskruitbosch+bugs
suing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2021-03-09 Thread Inyiltvv
seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2021-03-07 Thread Uivyfotv
Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 310999]

2021-03-07 Thread Uivyfotv
this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2021-03-07 Thread Mahdipedram60
because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list

[Bug 310999]

2014-02-21 Thread K1iwg4
eived this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2014-02-21 Thread Gervase Markham
://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999] Re: comodo seen issuing certificates unwisely

2013-10-03 Thread Bug Watch Updater
out this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2013-10-03 Thread Kwilson-r
unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2013-10-03 Thread 2-brian
://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2012-02-20 Thread Robin-comodo
Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2012-02-20 Thread Bugzilla-x-0x
ely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2012-02-20 Thread Kyle H
subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com

[Bug 310999]

2012-02-20 Thread Robin-comodo
to present to back up your allegation. Regards Robin Alden Comodo -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications ab

[Bug 310999]

2012-02-20 Thread Kyle H
s, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely To manage notifications about this bug go to: https://bugs.launchpad.net/nss/+bug/310999/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 310999]

2011-03-27 Thread Eddy-nigg
Guys, lets take discussions to mozilla-dev-security- pol...@lists.mozilla.org not here on the bug. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwise

[Bug 310999]

2011-03-27 Thread Paul C. Bryan
I reiterate my objection to Mozilla allowing the included certification authorities to outsource to third-party registration authorities. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title:

[Bug 310999]

2011-03-27 Thread Notordoktor
Robin, so the official stance from Comodo and its CEO - at least per bug 642395 Comment 73 - is that Iranian government should be blamed for this blunder? Well, in that case my last hopes that there still some tiny bit of common sense left behind Comodo's operation just ended in smoke. Meanwhile,

[Bug 310999]

2011-03-27 Thread Eddy-nigg
(In reply to comment #68) > We do still have a subset of our sales partners who are able to act as RAs, > but > since this debacle over CertStar we have retrofitted our own DV process into > the RA's ordering process in the vast majority of cases. > By 'our own DV process', I mean that Comodo perf

[Bug 310999]

2011-03-27 Thread Notordoktor
Created attachment 521253 Comodo fraudulent certificates Since proof is in the pudding - the above is being shipped via Windows Update/WSUS at the moment. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs

[Bug 310999]

2011-03-27 Thread Mozbugzilla
(In reply to comment #90) > No, I think the 9 certs are NOT publicly available. They are. I don't think it's necessary to attach them here, but believe me, they are publicly available. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. h

[Bug 310999]

2011-03-27 Thread Kai Engert
(In reply to comment #89) > > those 9 certs are now publicly available, so I see > no reason to keep that bug private any longer. No, I think the 9 certs are NOT publicly available. In fact, the attacker might not have received the certs, according to Comodo's blog. So, for the time being, it m

[Bug 310999]

2011-03-27 Thread Mozbugzilla
(In reply to comment #79) > The relevant Mozilla bug to that incident is bug 642395. It's time to open it up... those 9 certs are now publicly available, so I see no reason to keep that bug private any longer. -- You received this bug notification because you are a member of Ubuntu Bugs, which i

[Bug 310999]

2011-03-27 Thread Notordoktor
Wow, and login.skype.com, login.yahoo.com, www.google.com and mail.google.com - just excellent. OK, it's official - Comodo is now 4.5 times more lame than Verisign. :-P Their verification process must completely rock, must be just another "glitch in our validation system" - (C) Patricia, Certstar A

[Bug 310999]

2011-03-27 Thread Notordoktor
Gets even better - addons.mozilla.org was not enough, Comodo has been also "creating trust online" by issuing fraudulent certificate for login.live.com (Windows Live ID): Microsoft Releases Security Advisory 2524375: http://blogs.technet.com/b/msrc/archive/2011/03/23/microsoft-releases-security-a

[Bug 310999]

2011-03-27 Thread Eddy-nigg
(In reply to comment #85) > Understandable, given that issuing certs is one of your company's businesses. > :-) However, I have to go with The H Security: The opinion of an editor isn't a decision factor I guess. > Security by obscurity? :P Someone should unlock it promptly, gets ridiculous. Agr

[Bug 310999]

2011-03-27 Thread Notordoktor
(In reply to comment #84) > Hey Doktor - the operation was successful - the patient died? This is > actually > not what we want. Don't kill the patient, root out the source of the problem. > Or yank the root. Understandable, given that issuing certs is one of your company's businesses. :-) Howe

[Bug 310999]

2011-03-27 Thread Eddy-nigg
Hey Doktor - the operation was successful - the patient died? This is actually not what we want. Don't kill the patient, root out the source of the problem. Or yank the root. Or whatever... As such why is bug 642395 restricted? -- You received this bug notification because you are a member of U

[Bug 310999]

2011-03-23 Thread Notordoktor
(In reply to comment #81) > in the mean time we face a tradeoff between greater availability (and > therefore > deeper penetration) of SSL and dodgy certs... I'm not sure what the best > solution is (and am perhaps more concerned about government interference with > CAs than technical issues). Wh

[Bug 310999]

2011-03-23 Thread Ben-bucksch
I stand by my comment 72. A CA must not be allowed to outsource central functions of the CA, including key signing, verification and server administration. All entities who can, technically or organizationally, perform these functions, must be included in the audits, being checked physically. We MU

[Bug 310999]

2011-03-23 Thread Sam Johnston
While I agree with your sentiment (and don't particularly like the way this was handled – if the issuance issue was fixed then what's with the secrecy?), I think the underlying problem is going to require a more drastic solution than playing whack-a-mole with CAs. The TOR blog post references a few

[Bug 310999]

2011-03-23 Thread Notordoktor
(In reply to comment #79) > The relevant Mozilla bug to that incident is bug 642395. Thanks for the pointer, but that bug is: 1/ Restricted (why still restricted, I have no idea, it's leaked all over the web) 2/ Marked as RESOLVED FIXED. While that particular *incident* might have been fixed, t

[Bug 310999]

2011-03-23 Thread Ben-bucksch
The relevant Mozilla bug to that incident is bug 642395. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/310999 Title: comodo seen issuing certificates unwisely -- ubuntu-bugs mailing list ubuntu-bu

[Bug 310999]

2011-03-23 Thread Notordoktor
So, how much is too much? https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion http://blog.mozilla.com/security/2011/03/22/firefox-blocking-fraudulent-certificates/ This issue was reported to us by the *Comodo Group, Inc.*, the certificate autho

[Bug 310999] Re: comodo seen issuing certificates unwisely

2010-12-06 Thread Jesse Mortenson
I am seeing the "This connection is untrusted" warnings in Firefox 3.6.12 on Ubuntu 10.10 for sites with certificates from Comodo. The same sites work fine in Firefox 3.6.x on Windows XP. Sites include: https://contractor.lexisnexis.com/CS/welcome.do?justanswer http://wingsguate.org/civicrm/contri

[Bug 310999] Re: comodo seen issuing certificates unwisely

2010-09-18 Thread Bug Watch Updater
** Changed in: nss Importance: Unknown => High -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.c

[Bug 310999] Re: comodo seen issuing certificates unwisely

2010-05-17 Thread Bug Watch Updater
** Changed in: nss Status: Confirmed => In Progress -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-03-20 Thread Martin Pitt
Alexander confirms that no action is required from our side any more. ** Changed in: nss (Ubuntu Jaunty) Status: Triaged => Won't Fix ** Changed in: nss (Ubuntu Intrepid) Status: Triaged => Won't Fix ** Changed in: nss (Ubuntu Hardy) Status: Triaged => Won't Fix ** Changed

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-02-17 Thread Rick Spencer
** Changed in: nss (Ubuntu Jaunty) Assignee: (unassigned) => Alexander Sack (asac) ** Changed in: ca-certificates (Ubuntu Jaunty) Assignee: (unassigned) => Alexander Sack (asac) -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug no

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-02-02 Thread Steve Langasek
Information on mozilla mailing lists indicates that Comodo has followed up on the improperly issued certificates, and that revocations of the affected certificates have been published in a crl: http://www.mail- archive.com/dev-tech-cry...@lists.mozilla.org/msg05818.html So I don't see that there's

Re: [Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-28 Thread Alexander Sack
On Fri, Jan 16, 2009 at 01:54:17AM -, Steve Langasek wrote: > Still in a holding pattern here, not blocking alpha-3 on this. Do we > think we can get a resolution for alpha-4? > > ** Changed in: ca-certificates (Ubuntu Jaunty) >Target: jaunty-alpha-3 => jaunty-alpha-4 > Upstream sti

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-15 Thread Steve Langasek
Still in a holding pattern here, not blocking alpha-3 on this. Do we think we can get a resolution for alpha-4? ** Changed in: ca-certificates (Ubuntu Jaunty) Target: jaunty-alpha-3 => jaunty-alpha-4 -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You

Re: [Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-06 Thread Alexander Sack
On Tue, Jan 06, 2009 at 01:58:37PM -, Jamie Strandboge wrote: > Regarding ca-certificates, while this problem is unfortunate, it is > clear that simply removing the cert is not the answer because thousands > of perfectly valid certificates would be marked invalid. If a subset of > Comodo is to

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-06 Thread Jamie Strandboge
Regarding ca-certificates, while this problem is unfortunate, it is clear that simply removing the cert is not the answer because thousands of perfectly valid certificates would be marked invalid. If a subset of Comodo is to be invalidated, we need to consider Mozilla's rationale and implementatio

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-04 Thread Alexander Sack
we should decide on the blocking status for stable ubuntu releases, once we decided what to do for jaunty. ** Changed in: ca-certificates (Ubuntu Dapper) Importance: Undecided => High Status: New => Triaged ** Changed in: ca-certificates (Ubuntu Gutsy) Importance: Undecided => High

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-04 Thread Alexander Sack
blocking next alpha so we get a decision soon. ** Changed in: ca-certificates (Ubuntu Jaunty) Target: None => jaunty-alpha-4 ** Changed in: ca-certificates (Ubuntu Jaunty) Target: jaunty-alpha-4 => jaunty-alpha-3 -- comodo seen issuing certificates unwisely https://bugs.launchpad.

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-04 Thread Alexander Sack
i will defer decision for the ca-certificates package to the ubuntu security team. If they make a decision i will also communicate their rational to NSS upstream. ** Changed in: ca-certificates (Ubuntu) Importance: Undecided => High Status: New => Triaged -- comodo seen issuing certifi

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-04 Thread Alexander Sack
i will follow upstream decision on nss package. ** Changed in: nss (Ubuntu) Importance: Undecided => High Status: New => Triaged -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bug

Re: [Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-04 Thread Alexander Sack
On Fri, Jan 02, 2009 at 02:32:54PM -, Gabriel de Perthuis wrote: > DIY way to quit trusting these certificates: > > sudo sed -ri '/comodo|utn|addtrust/Is/^!*/!/' /etc/ca-certificates.conf; > sudo update-ca-certificates > nss doesnt use the ca-certificates package, but uses its own cert store

[Bug 310999] Re: comodo seen issuing certificates unwisely

2009-01-02 Thread Gabriel de Perthuis
DIY way to quit trusting these certificates: sudo sed -ri '/comodo|utn|addtrust/Is/^!*/!/' /etc/ca-certificates.conf; sudo update-ca-certificates -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubu

[Bug 310999] Re: comodo seen issuing certificates unwisely

2008-12-30 Thread Jeffrey Baker
Ubuntu has the opportunity to exercise some editorial judgment here by removing the cert regardless of the Mozilla project's decision. This cert authority has clearly breached their duty to users to issue certs only to verified parties. Since these certs are installed system-wide, and are used by

[Bug 310999] Re: comodo seen issuing certificates unwisely

2008-12-24 Thread Bug Watch Updater
** Changed in: nss Status: Unknown => Confirmed -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubu

[Bug 310999] Re: comodo seen issuing certificates unwisely

2008-12-24 Thread Philipp Kern
Well, I would like to defer to Mozilla's judgement here, as it comes from their truststore. On the other hand we do not have the possibility, to my knowledge, to add an intermediate CA to the package with some negative trust value. So we would need to prune Comodo completely. As stated CertStar

[Bug 310999] Re: comodo seen issuing certificates unwisely

2008-12-23 Thread Scott Dier
** Summary changed: - comodo seen issuing CAs unwisely + comodo seen issuing certificates unwisely -- comodo seen issuing certificates unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- u

[Bug 310999] Re: comodo seen issuing CAs unwisely

2008-12-23 Thread Scott Dier
Even more: http://groups.google.com/group/mozilla.dev.tech.crypto/browse_thread/thread/9c0cc829204487bf?pli=1 -- comodo seen issuing CAs unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 310999] [NEW] comodo seen issuing CAs unwisely

2008-12-23 Thread Scott Dier
*** This bug is a security vulnerability *** Public security bug reported: http://blog.startcom.org/?p=145 Comodo, or one of its resellers, has been observed selling certificates without serious domain control checks or other verification. There should be some consideration for removing the imp

[Bug 310999] Re: comodo seen issuing CAs unwisely

2008-12-23 Thread Scott Dier
http://it.slashdot.org/article.pl?sid=08/12/23/0046258 Has some discussion on this topic. -- comodo seen issuing CAs unwisely https://bugs.launchpad.net/bugs/310999 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing