James-E-A / cerdicator

Enhanced TLS indicator with an emphasis on information about the Root Certificate Authority from which the connection's authenticity is derived
https://addons.mozilla.org/en-US/firefox/addon/cerdicator/
1 stars 3 forks source link

OCSP: Indicate if Must-Staple was claimed, but no staple was provided #12

Open James-E-A opened 4 years ago

James-E-A commented 4 years ago

https://discourse.mozilla.org/t/webrequest-getsecurityinfo-certificates-pem-format-or-at-least-include-extensions/67138/2

Blocks #7

James-E-A commented 4 years ago

turns out, I'm just blind.

await webRequest.getSecurityInfo(… rawDER: true});
James-E-A commented 4 years ago

it's dangerous to go alone; take this!

https://github.com/lapo-luchini/asn1js/blob/1.2.1/asn1.js

James-E-A commented 4 years ago

…if we're doing the ASN parsing ourselves, how much will we have to worry about potentially malformed or malicious data?

Does Firefox at least enforce its being DER?