Yes, certificate validation on Linux is a mess. As others have said different applications require a root store in different formats or locations, but it is worse than that. Most fill the content of these root stores by copying Mozilla's root store and removing Mozilla-specific attributes from the roots because applications can't read these attributes. But Mozilla has repeatedly said that using their root store while ignoring these attributes is insecure.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| What's the future of OCSP stapling? Is CRL reintroducing the downtime problem? | 18 | 952 | April 25, 2025 | |
| Sunsetting of OCSP in favor of older technology? | 23 | 3261 | August 1, 2024 | |
| Windows Live Mail revocation warning | 29 | 12111 | March 14, 2017 | |
| Google Proposes Reducing TLS Cert Life Span to 90 Days | 61 | 6358 | July 19, 2023 | |
| Revisiting CRL in light of CRLite | 3 | 1999 | January 21, 2020 |