← Back to team overview

desktop-packages team mailing list archive

[Bug 837557] Re: fraudulent DigiNotar certificate issuance

 

@Olivier Mengué
I am working on updates for NSS and ca-certificates to address this system wide.

@Anonymous
Seamonkey is currently not in a good state, but I will try to get an update for it eventually.  In the mean time, the NSS update should take care of this security issue for most use cases.

** Description changed:

+ NOTE: The Firefox update causes a regression for certain Dutch sites
+ which is being tracked in Bug #838322.
+ 
  WORKAROUND (from blog post):
  http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert
  
  -------------------------------------------------
  
  http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-
  certificate/

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to thunderbird in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
  fraudulent DigiNotar certificate issuance

Status in “ca-certificates” package in Ubuntu:
  New
Status in “firefox” package in Ubuntu:
  Fix Released
Status in “nss” package in Ubuntu:
  New
Status in “qt4-x11” package in Ubuntu:
  New
Status in “thunderbird” package in Ubuntu:
  In Progress
Status in “xulrunner-1.9.2” package in Ubuntu:
  Invalid
Status in “ca-certificates” source package in Lucid:
  New
Status in “firefox” source package in Lucid:
  Fix Released
Status in “nss” source package in Lucid:
  New
Status in “qt4-x11” source package in Lucid:
  New
Status in “thunderbird” source package in Lucid:
  In Progress
Status in “xulrunner-1.9.2” source package in Lucid:
  Fix Released
Status in “ca-certificates” source package in Maverick:
  In Progress
Status in “firefox” source package in Maverick:
  Fix Released
Status in “nss” source package in Maverick:
  New
Status in “qt4-x11” source package in Maverick:
  New
Status in “thunderbird” source package in Maverick:
  In Progress
Status in “xulrunner-1.9.2” source package in Maverick:
  Fix Released
Status in “ca-certificates” source package in Natty:
  In Progress
Status in “firefox” source package in Natty:
  Fix Released
Status in “nss” source package in Natty:
  New
Status in “qt4-x11” source package in Natty:
  New
Status in “thunderbird” source package in Natty:
  In Progress
Status in “xulrunner-1.9.2” source package in Natty:
  Triaged
Status in “ca-certificates” source package in Oneiric:
  New
Status in “firefox” source package in Oneiric:
  Fix Released
Status in “nss” source package in Oneiric:
  New
Status in “qt4-x11” source package in Oneiric:
  New
Status in “thunderbird” source package in Oneiric:
  In Progress
Status in “xulrunner-1.9.2” source package in Oneiric:
  Invalid
Status in “ca-certificates” package in Debian:
  Fix Released

Bug description:
  NOTE: The Firefox update causes a regression for certain Dutch sites
  which is being tracked in Bug #838322.

  WORKAROUND (from blog post):
  http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert

  -------------------------------------------------

  http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-
  certificate/

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions


References