Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Give root certs and 'allow list' of what sites they are allowed to verify?

  • 2 balasan
  • 2 ada masalah ini
  • 3 paparan
  • Balasan terakhir oleh DStaal

more options

More a feature request than anything: I think it would be a good idea to have an optional whitelist for what sites a root cert is allowed to verify. A common situation would be a corporate root cert - if browser could be configured to only allowed to be a CA for sites within that company the users (employees in this case) could be sure that the company wasn't eavesdropping on their browsing to other websites, while allowing them to create and revoke certs for their own at will. (But I remember at least one news story recently where this would have helped the more general public when a CA started authorizing fake sites.)

More a feature request than anything: I think it would be a good idea to have an optional whitelist for what sites a root cert is allowed to verify. A common situation would be a corporate root cert - if browser could be configured to only allowed to be a CA for sites within that company the users (employees in this case) could be sure that the company wasn't eavesdropping on their browsing to other websites, while allowing them to create and revoke certs for their own at will. (But I remember at least one news story recently where this would have helped the more general public when a CA started authorizing fake sites.)

Penyelesaian terpilih

Feedback to the developers of Firefox and feature requests can be submitted here: https://input.mozilla.org/en-US/feedback

Baca jawapan ini dalam konteks 👍 1

All Replies (2)

more options

Penyelesaian Terpilih

Feedback to the developers of Firefox and feature requests can be submitted here: https://input.mozilla.org/en-US/feedback

more options

Thanks, I was looking for a link to feature requests on this site and couldn't find one.