Hi,

> That would be unfortunate for security for people to download a blob of
> certificates to trust over an unauthenticated channel. What could possibly
> go wrong there?

Especially as FF will try to import them if you try to download them via
HTTP and they come in PEM format (not sure about DER). Happens to me
every time that I forget that little issue.

Ralph
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to