Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-5343

gnutls should respect Mozilla's time-based distrust of certificates

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-9.0.0
    • gnutls
    • None
    • Low
    • rhel-sst-security-crypto
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      In 2019, a mechanism has been added to NSS to assert time-based distrust of CA certificates through special PKCS#11 attribute values: CKA_NSS_

      {SERVER,EMAIL}

      _DISTRUST_AFTER, which forbid the use of certificates issued by the CA after that time:
      https://wiki.mozilla.org/CA/Additional_Trust_Changes#Distrust_After

      Since then these attributes are being used for CAs such as TrustCor:
      https://bugzilla.mozilla.org/show_bug.cgi?id=1803453

      As GnuTLS also uses PKCS#11 trust store, it should respect these attributes and distrust the certificates based on that information.

              dueno@redhat.com Daiki Ueno
              dueno@redhat.com Daiki Ueno
              Daiki Ueno Daiki Ueno
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: