Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

security.osclientcerts.autoload in FIrefox 68.9.0

  • 6 پاسخ
  • 1 has this problem
  • 1 view
  • آخرین پاسخ توسّط Mike Kaply

more options

Hi.

I have a problem using the p12 certificates stored in Windows. security.osclientcerts.autoload is set in the registry under CU and LM under \SOFTWARE\Policies\Mozilla\Firefox\Preferences >>"security.osclientcerts.autoload"=dword:00000001 When checking about:config it's also set to true. The good thing: The certificates show up in Firefox version 77.0.1, where the certificates are listed. The bad thing: as standard browser we use is Firefox ESR version 68.9.0, where the certificates are not listed.

What I have seen by now security.osclientcerts.autoload has been implemented in ESR version 68.4.x .... is that the only version oder also for newer ones ?

And if also for newer ones, what could be the problem,.... and / or the solution for this problem ?

Appreciate for your help.

Kind regards Tom

Hi. I have a problem using the p12 certificates stored in Windows. security.osclientcerts.autoload is set in the registry under CU and LM under \SOFTWARE\Policies\Mozilla\Firefox\Preferences >>"security.osclientcerts.autoload"=dword:00000001 When checking about:config it's also set to true. The good thing: The certificates show up in Firefox version 77.0.1, where the certificates are listed. The bad thing: as standard browser we use is Firefox ESR version 68.9.0, where the certificates are not listed. What I have seen by now security.osclientcerts.autoload has been implemented in ESR version 68.4.x .... is that the only version oder also for newer ones ? And if also for newer ones, what could be the problem,.... and / or the solution for this problem ? Appreciate for your help. Kind regards Tom

Chosen solution

We were unable to back port osclient certs to Firefox 68. The Firefox 78 ESR will be out soon and will have this functionality.

You could theoretically take the osclientcerts.dll from Firefox 77 and use policy to add that DLL as a new security device and it should work on Firefox 68.

Read this answer in context 👍 1

All Replies (6)

more options

Chosen Solution

We were unable to back port osclient certs to Firefox 68. The Firefox 78 ESR will be out soon and will have this functionality.

You could theoretically take the osclientcerts.dll from Firefox 77 and use policy to add that DLL as a new security device and it should work on Firefox 68.

more options

Hi Mike,

thanks for your answer. I copied the osclientcerts DLL from Firefox 77 to the root of firefox 68esr and added module manually to 68esr. This worked fine - the certificates are now listed in firefox 68esr and working. To avoid adding the cryptography module manually on each firefox, is there a possibility to load the dll via script,.... batch or powershell or regkey or similar ?

Appriciate for your help. Kind regards Tom

Modified by t.hirtl

more options

You could use the SecurityDevices policy (which boils down to a regkey)

https://github.com/mozilla/policy-templates/blob/master/README.md#securitydevices

more options

Hi again,

is it possible, that security.osclientcerts.autoload doesn't work anymore with version 69.10.0 ? It worked well with 69.9.0 and after the update the Cryptographie module needs to be loaded by hand again.

Kind regards Tom

more options

I assume you mean 68.10.10? Firefox should have preserved the PKCS configuration. It works after you readd it as a security module?

more options

I'm going to assume everything is working with 78?