Closed Bug 1037906 Opened 10 years ago Closed 9 years ago

Equifax: Still valid 1024 certificates

Categories

(CA Program :: CA Certificate Root Program, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: kurt, Assigned: rick_andrews)

References

Details

(Whiteboard: BR Compliance - 1024 bit certs)

I'm have a list of about 12000 certificates that are still valid, haven't been revoked and have a 1024 bit key. Over 1000 of those are still being used. They're all issued by: C=US, O=Equifax, OU=Equifax Secure Certificate Authority
Assignee: kwilson → rick_andrews
Whiteboard: BR Compliance - 1024 bit certs
Rick: any news here? Gerv
Equifax is an 1024-bit root anyway, so it is best to deal with this by removing the root, which there is already a bug on.
Kurt, Would you please attach the current list of such sites to Bug #986019 Then I think we can close this bug as a duplicate of Bug #986019. Do you agree?
A list of all site that uses the Equifax root where the certificate is still valid would be better.
Closing this bug because the Websites and Code Signing trust bits were turned off for this 'Equifax Secure CA' root cert in Firefox 44.
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Product: mozilla.org → NSS
Product: NSS → CA Program
You need to log in before you can comment on or make changes to this bug.