Update Firefox 101.0.1. Strengthening Mozilla's requirements for Certificate Authorities

A corrective release of Firefox 101.0.1 is now available, notable for its enhanced sandbox isolation on the Windows platform. The new version includes, by default, blocking access to the Win32k API (components of Win32 GUI that operate at the kernel level) from isolated content processing processes. This change was made ahead of the Pwn2Own 2022 competition, set to take place from May 18-20. Participants in Pwn2Own will demonstrate working exploitation techniques for previously unknown vulnerabilities and will receive substantial rewards if successful. For instance, the bounty for bypassing sandbox isolation in Firefox on Windows is set at $100,000.

Other changes include fixing the issue with subtitle display in picture-in-picture mode when using Netflix and addressing the bug related to the unavailability of certain commands in the picture-in-picture window.

Additionally, there are new requirements in Mozilla's root certificate storage policy. These changes, aimed at addressing some long-standing issues with the revocation of TLS server certificates, will take effect on June 1.

The first change concerns the inclusion of revocation reason codes (RFC 5280), which certification authorities will now be required to specify in certain cases of certificate revocation. Previously, some certification authorities either failed to provide such data or designated it formally, complicating the tracking of revocation reasons. serversFrom now on, correctly filling out reason codes in Certificate Revocation Lists (CRLs) will be mandatory and will help distinguish cases related to key compromise and policy violations from non-security-related issues, such as changes in organizational information or premature certificate replacement. domain or early replacement of the certificate.

The second amendment requires certificate authorities to send the complete URLs of Certificate Revocation Lists (CRL) to the Common CA Certificate Database (CCADB). This change will allow for the full accounting of all revoked TLS certificates and enable Firefox to preload more comprehensive data about revoked certificates that can be used for verification without sending a request to the certificate authorities' servers during the TLS connection establishment process.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster