Open Bug 1618807 Opened 5 years ago Updated 2 years ago

Allow users to customize auto-importing root certificates more easily

Categories

(Firefox :: Security, enhancement, P3)

enhancement

Tracking

()

People

(Reporter: johannh, Unassigned)

References

(Blocks 1 open bug)

Details

With security.certerrors.mitm.auto_enable_enterprise_roots being set to true we will automatically attempt to fix certificate errors by importing OS roots. While this is desirable for most of our users (given that they don't have an alternative to using the internet with these imported roots), there's evidently a group of more advanced users who would prefer to have better control of this feature.

Since the size of that group might change due to events like Lenovo Superfish and it might include technically less advanced users, it's probably a good idea to make it easier to configure the behavior.

At the very least we should probably expose this option in about:preferences. In addition, I could imagine an optional "middle-ground" setting, where Firefox would ask the user whether they want to keep the enterprise root pref enabled if it fixes the connection, potentially displaying the certificate chain that successfully established a connection.

Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.