X
點擊此處開啟此網站的行動版。

技術支援討論區

when will Mozilla support Expect-CT, a new security header

已張貼

"Expect-CT is a new security header which is, at the moment, only supported by Chrome and Opera browsers. It allows a website to instruct the browser to reject any certificate not found in Certificate Transparency, a read-only public log of certificates which can be audited. Because Expect-CT is an HTTP header, it is a trust-on-first-use protocol that relies on long-term caching to ensure security. While Expect-CT does not prevent a compromised Certificate Authority from issuing a fake certificate, it does limit the damage by forcing the addition of the certificate to the log. The domain owner can then report the fake certificate and attempt to get it revoked." [Protonmail]

"Expect-CT is a new security header which is, at the moment, only supported by Chrome and Opera browsers. It allows a website to instruct the browser to reject any certificate not found in Certificate Transparency, a read-only public log of certificates which can be audited. Because Expect-CT is an HTTP header, it is a trust-on-first-use protocol that relies on long-term caching to ensure security. While Expect-CT does not prevent a compromised Certificate Authority from issuing a fake certificate, it does limit the damage by forcing the addition of the certificate to the log. The domain owner can then report the fake certificate and attempt to get it revoked." [Protonmail]

被選擇的解決方法

Expect-CT (Certificate Transparency) isn't really a new concept as it goes back to 2014.

Certificate Transparency has been implemented in Firefox for telemetry, but is disabled because of negative impact on the performance.

If you want to spend some time on reading:


security.pki.certificate_transparency.mode (0 | 1)


Some related bug reports:

  • Bug 1281469 - Implement Certificate Transparency support (RFC 6962)
  • Bug 1349941 - Support Expect-CT for Opting-in to Certificate Transparency [RW]
  • Bug 1353216 - certificate transparency signature verifications negatively impact TLS handshake performance
  • Bug 1355903 - Re-enable Certificate Transparency telemetry collection

(please do not comment in bug reports
https://bugzilla.mozilla.org/page.cgi?id=etiquette.html
)

從原來的回覆中察看解決方案 0
引用

額外的系統細節

已安裝的外掛程式

not related to question

應用程式

  • User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:70.0) Gecko/20100101 Firefox/70.0

更多資訊

cor-el
  • Top 10 Contributor
  • Moderator
17472 個解決方法 157915 個答案

選擇的解決方法

Expect-CT (Certificate Transparency) isn't really a new concept as it goes back to 2014.

Certificate Transparency has been implemented in Firefox for telemetry, but is disabled because of negative impact on the performance.

If you want to spend some time on reading:


security.pki.certificate_transparency.mode (0 | 1)


Some related bug reports:

  • Bug 1281469 - Implement Certificate Transparency support (RFC 6962)
  • Bug 1349941 - Support Expect-CT for Opting-in to Certificate Transparency [RW]
  • Bug 1353216 - certificate transparency signature verifications negatively impact TLS handshake performance
  • Bug 1355903 - Re-enable Certificate Transparency telemetry collection

(please do not comment in bug reports
https://bugzilla.mozilla.org/page.cgi?id=etiquette.html
)

Expect-CT (Certificate Transparency) isn't really a new concept as it goes back to 2014. Certificate Transparency has been implemented in Firefox for telemetry, but is disabled because of negative impact on the performance. If you want to spend some time on reading: *https://developer.mozilla.org/en-US/docs/Web/Security/Certificate_Transparency *https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expect-CT *https://wiki.mozilla.org/PKI:CT ---- *https://dxr.mozilla.org/mozilla-release/source/security/manager/ssl/security-prefs.js security.pki.certificate_transparency.mode (0 | 1) ---- Some related bug reports: *[https://bugzilla.mozilla.org/show_bug.cgi?id=1281469 Bug 1281469] - Implement Certificate Transparency support (RFC 6962) *[https://bugzilla.mozilla.org/show_bug.cgi?id=1349941 Bug 1349941] - Support Expect-CT for Opting-in to Certificate Transparency [RW] *[https://bugzilla.mozilla.org/show_bug.cgi?id=1353216 Bug 1353216] - certificate transparency signature verifications negatively impact TLS handshake performance *[https://bugzilla.mozilla.org/show_bug.cgi?id=1355903 Bug 1355903] - Re-enable Certificate Transparency telemetry collection (<i>please do not comment in bug reports<br>https://bugzilla.mozilla.org/page.cgi?id=etiquette.html</i>)
這篇文章有幫助嗎?
引用
問個問題

如果您還沒有帳號,您必須先 登入您的帳號 來回覆文章。請 開始一個新問題