Firefox and Thunderbird updates
Firefox and Thunderbird updates
New versions of Firefox (6.0.2 and 3.6.22)
and Thunderbird (6.0.2, 7.0 beta, and
3.1.14) are out. These releases remove
trust exceptions for certificates issued by Staat der Nederlanden.
"DigiNotar issues certificates as part of the Dutch government's
PKIoverheid (PKIgovernment) program. These certificates are issued from a
different DigiNotar-controlled intermediate, and chain up to the Dutch
government CA (Staat der Nederlanden). The Dutch government's Computer
Emergency Response Team (GovCERT) indicated that these certificates are
issued independently of DigiNotar's other processes and that, in their
assessment, these had not been compromised. The Dutch government therefore
requested that we exempt these certificates from the removal of trust,
which we agreed to do in our initial security update early this week. The
Dutch government has since audited DigiNotar's performance and rescinded
this assessment. We are now removing the exemption for these certificates,
meaning that all DigiNotar certificates will be untrusted by Mozilla
products.
"