Hacker News new | past | comments | ask | show | jobs | submit login

Specifically Mozilla provides a flag which has the effect of accepting the additional corporate trust only.

So e.g. if Microsoft decides for $1B cash they trust Honest Abe's Totally American For-Profit Church O'Certs and ships a Windows 10 update to enable that, Firefox still won't accept Abe's bogus google.com cert even with the enterprise mode on. But if your head of IT decides they'd very much like to issue certificates for internal-test-server.example and pushes a new root CA from their laptop via Group Policy, Firefox in enterprise mode will trust that cert because it was local policy.

Basically the idea is Mozilla won't substitute Microsoft's decisions for their own, but your own local certificate policies are different. So you can opt into the latter in Firefox, but not the former.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: