Repository navigation
Why do you trust CNNIC? #15073
Description
Activity
I want to clarify: this is in relation to including cnnic is the default trusted certs? Correct?
Hello @buckle2000,
The current procedure for root CA trust is to mirror the list provided by Network Security Services (NSS).
Feel free to raise a PR to update that list, or the version that's embedded innode(similar to #13279).- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.securityIssues and PRs related to security.Issues and PRs related to security.questionIssues asking questions about Node.js.Issues asking questions about Node.js.
on Aug 29, 2017 Hi! We take TLS security seriously. We follow recommendations set up by major browser vendors (Mozilla, Google, and others) with regards to CA. In fact, we have already distrusted all new CNNIC-issued certificates in accordance with Mozilla since #1895 (landed two years ago), which is in the latest release of all support release branches.
If you believe the a supported version of Node.js does not distrust some CNNIC-issued certificates when it should, please email security@nodejs.org as documented in https://github.com/nodejs/node/blob/master/README.md
/cc @shigeki
Edit: Fix truncated response.
Yes, the CNNIC root certs is now included but the certificates issued by CNNIC are filtered with the whitelist of https://github.com/nodejs/node/blob/master/src/CNNICHashWhitelist.inc which is provided by Mozilla.
Recently, the CNNIC root cert was removed in Mozilla's root certs list in https://bugzilla.mozilla.org/show_bug.cgi?id=1356623 and we are waiting for Firefox56 to be stable.
After releasing Firefox56, we are going to update root certs so that all certs issued by CNNIC will be distrusted.Reacted by James M SnellClosing as I described above.
Firefox56 was released on September 28, 2017.
https://developer.mozilla.org/en-US/Firefox/Releases/56
@jasnell @TimothyGu
You really shouldn't trust CNNIC.