This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

are DigiNotar certificates safe, because it reads they are not trusted. can they be safely removed?

  • 4 replies
  • 1 has this problem
  • 4 views
  • Last reply by cor-el

more options

in firefox options, privacy and security, certificates, there are 2 DigiNotar server certificates listed; DigiNotar Root CA and DigiNotar PKIoverheid CA Organisatie- G2.

about:preferences#privacy

in firefox options, privacy and security, certificates, there are 2 DigiNotar server certificates listed; DigiNotar Root CA and DigiNotar PKIoverheid CA Organisatie- G2. about:preferences#privacy

All Replies (4)

more options

hi 1scotch, firefox contains these diginotar certificates in order to know to actively distrust them in case it ever comes across them in the wild, so it's best to leave them in place.

more options

diginotar certificates have been distrusted for a long time like say 3.6.22

People have mistakenly thought they were trusted or should be removed simply because they were listed.


a comment from Bug 699759 - Firefox 7 still contains Diginotar certificates on ubuntu and debian

Instead of simply removing DigiNotar, we have added special DigiNotar replacement certificates, that have the effect of explicitly distrusting the old DigiNotar certificates.
more options

interesting. thank you gentlemen.

more options

See also:

(please do not comment in bug reports
https://bugzilla.mozilla.org/page.cgi?id=etiquette.html
)