Lets Encryypt...
Why do you list Lets Encrypt SSL certificates as unsecure? Please add them to the recognized certificate issuers.
Toutes les réponses (6)
Most of Mozilla's own operations are fronted by Let's Encrypt certificates just fine (BTW Mozilla was one of the founding partners of Let's Encrypt back in the day) — and all the roots are present in the trust store.
You might need to be more specific, i.e. which site, and how the sslscan results look like for it.
jbr said
all the roots are present in the trust store.
Where is that trust store? Can I suppose that it will be included with Firefox derivatives like Waterfox too?
I updated an OLD waterfox on a Win10 install I hadn't used for a long time earlier this afternoon. I could connect to my Firefox account and activate sync.
Then I did something that forced me to restore a restoration point, which meant I had to install Waterfox again, and managed to activate the profile I had set up earlier. Sync seemed to work but did not in fact do anything, and opening accounts.firefox.com is impossible because of a certificate problem that can't be ignored.
Other sites also throw a warning that should not appear; mozilla.org for instance. I've already uninstalled and reinstalled Waterfox, to no avail.
Edge does connect without a glitch, and so does Firefox (I tried the Developer Edition).
The CA Root program at mozilla.org/about/governance/policies/security-group/certs/policy/#1-introduction mentions any distribution can modify the content to their liking. The certdata.txt store is described in firefox-source-docs.mozilla.org/security/nss/runbooks/rootstore.html
jbr said
The CA Root program at mozilla.org/about/governance/policies/security-group/certs/policy/#1-introduction mentions any distribution can modify the content to their liking.
Yes, I suppose that's a good thing. But for a browser that does offer a sync feature that's compatible with Firefox itself it would be a shot in the foot to remove these certificates.
And indeed, the Waterfox copies I run on a Win11 system are not affected. and neither was the copy on the now crippled Win10 machine before I had to roll back the OS. (Because I had uninstalled something I shouldn't; the OS is now restored to the point it was before I did that.)
The certdata.txt store is described in firefox-source-docs.mozilla.org/security/nss/runbooks/rootstore.html
Do I understand correctly that this file is built into the code, so you can't just take the certdata.txt file from a machine where everything works OK and copy it to the affected machine?
If so that really begs the question how it is possible for one install to work and another to stop working after an OS rollback.
Viewing the certificate for `accounts.firefox.com` in Firefox and in the affected Waterfox copy, everything is equal except that the latter seems to miss the ISRG Root X1 certificate.
EDIT: According to certmgr.exe, that root certificate *is* installed!
There is something fishy about this Waterfox install anyway; even before this particular issue struck I couldn't set it to the default browser because it doesn't show up in the list of options. That too is something I've never had before.
Modifié le
You might wanna check with their support, but if that was happening in Firefox I'd advise try from a separate profile, and remove the cert*/key*/sec*.db files with any trust customizations, and have them recreated.
I uninstalled WF once more, removed the old install folder that stlll had files from an ancient install in it, ran Auslogic's registry cleaner, rebooted, reinstalled WF, moved the %APPDATA%/Roaming/Waterfox profiles folder aside, and ... bingo. No more issues connecting to Mozilla sites, nor to some others that had been giving certificate warnings.
I then quit the browser, moved the old Waterfox profiles folder back, restarted the browser, and things still worked.