View previous topic :: View next topic |
Author |
Message |
lyallp Veteran
![Veteran Veteran](/images/ranks/rank_rect_5_vet.gif)
![](images/avatars/12785226974110e85e73ae3.jpg)
Joined: 15 Jul 2004 Posts: 1606 Location: Adelaide/Australia
|
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
1clue Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 05 Feb 2006 Posts: 2569
|
Posted: Thu Apr 07, 2011 11:35 pm Post subject: |
|
|
As I understand it, that blacklist is not maintained on your computer, but on servers at various certificate authorities. Your browser has the CA list but not individual certificates.
So I think you don't do anything. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Hu Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
Joined: 06 Mar 2007 Posts: 23100
|
Posted: Fri Apr 08, 2011 4:09 am Post subject: |
|
|
The fraudulent certificates were added to the Comodo CRL. However, because many users turn off CRL checking for privacy reasons, all the major vendors pushed a patch which hardcodes those certificates as untrusted. That patch is 3.6.16 for Firefox 3.6.x. I believe I saw a claim that Firefox 4.0 was released late enough that it also has the blacklist, but I do not have a citation for that handy. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|