Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] firefox SSL certs
- Date: Mon, 12 Sep 2011 12:44:02 +0900
- From: Darren Cook <darren@example.com>
- Subject: Re: [tlug] firefox SSL certs
- References: <4E6D3A61.6020409@example.com> <87sjo2pr6d.fsf@example.com> <4E6D5C1C.8050904@example.com> <CAM5TeUwMe=vVon42304Fxja8Lw6xY1AdXDnMJ+nTbogJzX0zWA@example.com>
- User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.21) Gecko/20110831 Thunderbird/3.1.13
>> But it turns out the .0 files (that are new) are just symbolic links to >> .pem files (that are not), and the linked filename tells me as much as I >> need to know. (BTW, the deleted .o file seems to correspond with the >> deleted DigiNotar_Root_CA.pem.) > > Given that DigiNotar was hacked and their certs revoked, wouldn't you > expect changes? Nope; I'm fine with that. It is the other changes/additions that happened at the same time that are confusing me. After a little more googling, I think what has happened is c_rehash got run yesterday (presumably by the firefox package update) and therefore created hashes for a couple of certificates that have been added since whenever it was last run. ("UbuntuOne-Go_Daddy" is one of them, and dates back to 2011-04-15, so it seems c_rehash does not get run very often!) And, regarding, packet ownership, the certificates for almost all of them are actually kept under /usr/share/ca-certificates/ which is owned by the ca-certificates package. So, the "problem" was simply that symbol links are not package-owned. It'd be nice if apt-file had an option to follow symlinks. So, satisfied I've just checked all the changes into git. Thanks for the replies and education. :-) Darren -- Darren Cook, Software Researcher/Developer http://dcook.org/work/ (About me and my work) http://dcook.org/blogs.html (My blogs and articles)
- References:
- [tlug] firefox SSL certs
- From: Darren Cook
- [tlug] firefox SSL certs
- From: Stephen J. Turnbull
- Re: [tlug] firefox SSL certs
- From: Darren Cook
- Re: [tlug] firefox SSL certs
- From: Shawn Brown
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] firefox SSL certs
- Next by Date: Re: [tlug] firefox SSL certs
- Previous by thread: Re: [tlug] firefox SSL certs
- Next by thread: Re: [tlug] firefox SSL certs
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links