{"id":383,"date":"2008-12-24T12:24:52","date_gmt":"2008-12-24T16:24:52","guid":{"rendered":"http:\/\/benjamin.smedbergs.us\/blog\/?p=383"},"modified":"2008-12-24T14:27:57","modified_gmt":"2008-12-24T18:27:57","slug":"how-to-disable-the-comodo-root-certificate-in-firefox","status":"publish","type":"post","link":"https:\/\/benjamin.smedbergs.us\/blog\/2008-12-24\/how-to-disable-the-comodo-root-certificate-in-firefox\/","title":{"rendered":"How to disable the Comodo reseller root certificate in Firefox"},"content":{"rendered":"<p><a href=\"http:\/\/it.slashdot.org\/article.pl?sid=08\/12\/23\/0046258\">Slashdot is a-buz<\/a>z (and rightly so!) with news that people have been able to obtain an <a href=\"https:\/\/blog.startcom.org\/?p=145\">SSL certificate for a domain they don&#8217;t own<\/a>, by applying with one of Comodo&#8217;s certificate resellers. It is clear that there has been a major breach of trust, but we&#8217;re not sure of the best general solution. There has been a <a href=\"http:\/\/groups.google.com\/group\/mozilla.dev.tech.crypto\/browse_thread\/thread\/9c0cc829204487bf#\">discussion in the mozilla.dev.tech.crypto newsgroup<\/a> about what steps Mozilla should take for this breach.<\/p>\n<p>In the meantime, I recommend disabling the root certificate used by this certificate authority, to avoid the possibility that other fraudulent certificates are floating around in the wild. Here&#8217;s how to disable the relevant CA root in Firefox:<\/p>\n<ol>\n<li>Open the preferences window\n<li>Select the &#8220;Advanced&#8221; tab\n<li>Select the &#8220;Encryption&#8221; sub-tab\n<li>Choose &#8220;View Certificates&#8221;<br \/>\n    <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-certprefs-dialog.png\" alt=\"Firefox Preferences Window: Advanced -&gt; Encryption -&gt; Certificates\" title=\"firefox-certprefs-dialog\" width=\"613\" height=\"503\" class=\"size-full wp-image-386\" style=\"display: block; padding: 10px;\" srcset=\"https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-certprefs-dialog.png 613w, https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-certprefs-dialog-300x246.png 300w\" sizes=\"auto, (max-width: 613px) 100vw, 613px\" \/><\/p>\n<li>Find and select the &#8220;AddTrust AB \/ AddTrust External CA Root&#8221; item\n<li>Choose the &#8220;Edit&#8217; button<br \/>\n    <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-rootcerts-dialog.png\" alt=\"Root Certificates Dialog\" title=\"firefox-rootcerts-dialog\" width=\"672\" height=\"671\" class=\"size-full wp-image-388\" style=\"display: block; padding: 10px;\" srcset=\"https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-rootcerts-dialog.png 672w, https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-rootcerts-dialog-150x150.png 150w, https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-rootcerts-dialog-300x299.png 300w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\" \/><\/p>\n<li>Remove all trust setting check-boxes.<br \/>\n   <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-editcert-dialog.png\" alt=\"Edit Certificate Dialog\" title=\"firefox-editcert-dialog\" width=\"445\" height=\"188\" class=\"size-full wp-image-387\" style=\"display: block; padding: 10px;\" srcset=\"https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-editcert-dialog.png 445w, https:\/\/benjamin.smedbergs.us\/blog\/wp-content\/uploads\/2008\/12\/firefox-editcert-dialog-300x126.png 300w\" sizes=\"auto, (max-width: 445px) 100vw, 445px\" \/>\n<\/ol>\n<p><em>Note:<\/em> disabling this root certificate will SSL websites validated by this Comodo reseller to stop working. That&#8217;s why you&#8217;re doing it, but if it&#8217;s your favorite website that stops working, please don&#8217;t blame me! If you&#8217;re really paranoid, you could also disable all Comodo roots: these include all the certificates with names like &#8220;AddTrust&#8221;, &#8220;Comodo CA Limited&#8221;, and &#8220;The UserTrust Network&#8221;.<\/p>\n<p>Thanks to Eddy Nigg for first <a href=\"http:\/\/groups.google.com\/group\/mozilla.dev.tech.crypto\/msg\/237eb8b6df7d987b\">providing<\/a> these instructions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Slashdot is a-buzz (and rightly so!) with news that people have been able to obtain an SSL certificate for a domain they don&#8217;t own, by applying with one of Comodo&#8217;s certificate resellers. It is clear that there has been a major breach of trust, but we&#8217;re not sure of the best general solution. There has [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,6],"tags":[138,199,64,200],"class_list":["post-383","post","type-post","status-publish","format-standard","hentry","category-mozilla","category-untagged","tag-certificate","tag-comodo","tag-firefox","tag-ssl"],"_links":{"self":[{"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/posts\/383","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/comments?post=383"}],"version-history":[{"count":12,"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/posts\/383\/revisions"}],"predecessor-version":[{"id":398,"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/posts\/383\/revisions\/398"}],"wp:attachment":[{"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/media?parent=383"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/categories?post=383"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/benjamin.smedbergs.us\/blog\/wp-json\/wp\/v2\/tags?post=383"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}