Is there any way of allowing users to add locally on their machine a 
certificate to the OneCRL scope?  (but don't allow local scope to override the 
mozilla-published one - it should always have priority)

back in september i revoked locally on my machine the WoSign roots and i tried 
to use the new certificate manager addon but not even that was able to revoke 
the WoSign cross-sign.

https://github.com/sidstamm/FirefoxCertificateManager/issues/56

how can i revoke locally such intermediates without revoking the root CA itself?

Adrian R.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to