Skip to content

Update guidance on licensing cert#803

Open
quexten wants to merge 5 commits intomainfrom
note-about-mitm-cert
Open

Update guidance on licensing cert#803
quexten wants to merge 5 commits intomainfrom
note-about-mitm-cert

Conversation

@quexten
Copy link
Copy Markdown
Contributor

@quexten quexten commented May 4, 2026

🎟️ Tracking

https://bitwarden.atlassian.net/browse/PM-36250

📔 Objective

The current contributing docs prescribe loading the licensing certificate as a root certificate into the OS keychain. This gives everyone with the root certificate - all bitwarden employees - the ability to spoof, intercept and tamper with all TLS traffic of all everyone who has this trusted root certificate in their keychain.

Instead of loading it into the keychain as a root certificate, this PR adds the ability to load it from a file, only for the specific scope of the bitwarden/server application, entirely eliminating this risk.

📸 Screenshots

@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages Bot commented May 4, 2026

Deploying contributing-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: c1487c0
Status: ✅  Deploy successful!
Preview URL: https://f2eb0416.contributing-docs.pages.dev
Branch Preview URL: https://note-about-mitm-cert.contributing-docs.pages.dev

View logs

@quexten quexten marked this pull request as ready for review May 4, 2026 03:41
@quexten quexten requested a review from a team as a code owner May 4, 2026 03:41
@quexten quexten requested a review from Thomas-Avery May 4, 2026 03:41
Comment thread docs/getting-started/server/guide.md Outdated
Comment thread docs/getting-started/server/guide.md Outdated
@quexten
Copy link
Copy Markdown
Contributor Author

quexten commented May 5, 2026

@Thomas-Avery Applied your feedback. Both good points!

@quexten quexten enabled auto-merge (squash) May 5, 2026 10:41
Copy link
Copy Markdown
Contributor

@theMickster theMickster left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor change that was caught by a local multi-agent Claude Code session.

Comment thread docs/getting-started/server/guide.md Outdated
Co-authored-by: Mick Letofsky <mletofsky@bitwarden.com>
@quexten quexten requested a review from Thomas-Avery May 5, 2026 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants