Opened 3 years ago

Last modified 3 years ago

#4145 new change

Remove anchor from SSL certificate chains

Reported by: matze Assignee:
Priority: P3 Milestone:
Module: Infrastructure Keywords:
Cc: Blocked By: #4073, #4144
Blocking: Platform: Unknown / Cross platform
Ready: yes Confidential: no
Tester: Unknown Verified working: no
Review URL(s):

Description

Some of our SSL certificate chains do include the root certificate, which is not a security flaw but slightly increases handshake latency.

What to do

Remove the root certificate bits from the chain files for the following domains resp. certificates:

  • easylist-downloads.adblockplus.org
  • downloads.adblockplus.org

Other items for that list may follow, although most of our other services have been checked already.

Change History (1)

comment:1 Changed 3 years ago by matze

  • Blocked By 4073 added
  • Type changed from defect to change
Note: See TracTickets for help on using tickets.