libera/#maemo/ Wednesday, 2021-07-21

bencohMaxdamantus: at this point I'd just trust a wildcard cert in browserd, and have the proxy use it01:40
bencohhmm, not sure browserd would accept it though01:41
bencoheither that, or disable cert verification in the browser, since the proxy is supposed to do that anyway01:41
MaxdamantusWildcard certs are not valid, otherwise I would use one of them in the proxy.01:46
Maxdamantusat least, wildcard certs for TLDs or above are not valid.01:47
MaxdamantusThat is, "CN=*" or "CN=*.com" are not valid (or rather, ignored), but "CN=foo.com" or "CN=*.foo.com" are valid.01:48
bencohno way to disable validation altogether?01:49
MaxdamantusI doubt it. tbh I wouldn't want to.01:50
bencohwhy? the proxy does the job01:50
MaxdamantusBecause if the proxy is not used for some reason (configuration reset, or maybe a random non-SSL-intercepting proxy is running), it shouldn't just trust all certs.01:56
Maxdamantusanyway, I suspect even in 2009, browser developers probably wouldn't have wanted to add that capability.02:00
MaxdamantusHeh, looks like that suspicion might have been wrong. Sounds like there used to be a "security.use_mozillapkix_verification" flag until Firefox 33, where they presumably got rid of that option.02:07

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!