Closed Bug 161709 Opened 22 years ago Closed 10 years ago

Enhance "manual trust" wording, make it clear this can add explicit trust, but does not remove indirect trust.

Categories

(Core Graveyard :: Security: UI, defect)

1.0 Branch
x86
Windows 2000
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 585352

People

(Reporter: junruh, Unassigned)

Details

(Whiteboard: [kerh-ehz][psm-cert-manager])

1.) Receive a signed email. 2.) Open the Cert Manager and click on Other Peoples tab. 3.) Edit the cert from the signer, edit the CA, and trust the CA, and click OK. 4.) Select "Do not trust the authenticity of this certificate" and click OK. 5.) Close the Cert Manager and Prefs panel. 6.) Read the signed email. What is expected. That the signature would be invalid, since the cert is not trusted. What happens: The signature is valid.
Keywords: nsbeta1
I think this is not a bug, but a confusion in our wording. The same wording is used for end user and web server certificiates, therefore this bug could be described as a server cert bug, too. While the text says "do not trust this certificate", we do not allow to explicitly allow to remove trust from a leaf cert. All we allow is to add explicit trust to an otherwise untrusted cert. However, a cert that is trusted by a trusted root CA, is still trusted, even if the user did not explicitly give trust to that cert. I suggest that we either mark this bug as invalid, or morph this bug into an enhancement request, to clarify the wording.
Changing summary
Summary: Edit Trust settings of Other People's certs have no effect on email signature → Enhance "manual trust" wording, make it clear this can add explicit trust, but does not remove indirect trust.
Product: PSM → Core
Whiteboard: [kerh-ehz]
QA Contact: junruh → ui
Version: psm2.4 → 1.0 Branch
Assignee: kaie → nobody
Whiteboard: [kerh-ehz] → [kerh-ehz][psm-cert-manager]
Bug 585352 has a bit more discussion and more people CCed, so forward duping.
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → DUPLICATE
Product: Core → Core Graveyard
You need to log in before you can comment on or make changes to this bug.