Bug 411121

Summary: doesn't "remember" that I no longer trust a CA
Product: [Fedora] Fedora Reporter: Nalin Dahyabhai <nalin>
Component: firefoxAssignee: Kai Engert (:kaie) (inactive account) <kengert>
Status: CLOSED UPSTREAM QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: rawhideCC: gecko-bugs-nobody, mcepl
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-12-05 13:34:00 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Nalin Dahyabhai 2007-12-04 21:51:27 UTC
Description of problem:
If I visit a site whose SSL certificate is signed by a CA, and then remove that
CA from my list of trusted CAs, I can reload the page without being prompted
about what is now an untrustworthy certificate.  I have to restart the browser
for the CA's removal to take effect.  This isn't what I'd expect.

Version-Release number of selected component (if applicable):
firefox-2.0.0.10-1.fc9

How reproducible:
Always

Steps to Reproduce:
1. Import our IS department's CA certificate, marking it trusted for use in
verifying web sites.
2. Visit internal site https://calendar.redhat.com/
3. From Edit/Preference's Advanced/Encryption tab, open the View Certificates
dialog, and from the Authorities tab, delete the certificate.
4. Attempt to reload the page.
  
Actual results:
No warnings.

Expected results:
The usual "certificate not signed by trusted authority" dialog.

Comment 2 Christopher Aillon 2007-12-05 12:09:54 UTC
This is kai's domain...

Comment 3 Kai Engert (:kaie) (inactive account) 2007-12-05 13:34:00 UTC
Yes, this is an upstream behavior, not something we introduce in the Red Hat or
Fedora packages.

I would dupe this to https://bugzilla.mozilla.org/show_bug.cgi?id=402710