Feature #24
More conservative SSL certificate handling
| Status: | New | Start: | 05/29/2010 | |
|---|---|---|---|---|
| Priority: | Normal | Due date: | ||
| Assigned to: | Alguno | % Done: |
0% |
|
| Category: | NNTPGrab Core | |||
| Target version: | - | |||
| Votes: | 0 |
Description
This feature request is copied over from the old website
Allow user to accept, temporary accept, or deny a (self-signed) SSL certificate. A user should only be able to automatically accept a SSL certificate if the certificate is in the list of certificate authorities the user trusts (see e.g. ca-certificates on Debian/Ubuntu). If the certificate is not in earlier mentioned web of trust present the user with an informative dialog where the user can permanently accept, temporarily accept, or deny the certificate authority. This would include even a self-signed certificate. Ideally, the implementation would also adhere GTK/GNOME dialog standards. A reference implementation is Mozilla Firefox 3.0. Because this feature is fundamental for proper usage and security of SSL it is highly important.
Also available in: Atom PDF
NNTPGrab

