Skip to content

docs: explain how to trust the Caddy authority in Firefox - #971

Open
ker0x wants to merge 1 commit into
dunglas:mainfrom
ker0x:docs/firefox-tls
Open

ker0x wants to merge 1 commit into
dunglas:mainfrom
ker0x:docs/firefox-tls

Conversation

@ker0x

@ker0x ker0x commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Firefox uses its own trust store, so the commands in docs/tls.md (which update the system trust store) are not enough for it.

Also, when the caddy_data volume is removed (e.g. docker compose down -v), Caddy generates a new local authority with the same name as the previous one. If Firefox still trusts the old root, it rejects the new chain with SEC_ERROR_BAD_SIGNATURE instead of the usual SEC_ERROR_UNKNOWN_ISSUER (reported in #969 (comment)).

Changes

  • Docs: add a Firefox section to docs/tls.md, explaining how to trust the authority (import root.crt, or enable security.enterprise_roots.enabled) and how to fix SEC_ERROR_BAD_SIGNATURE after the authority is regenerated.

Testing

Reproduced with Firefox (Playwright build) against FrankenPHP v1.13.0 / Caddy v2.11.7:

  • fresh profile: SEC_ERROR_UNKNOWN_ISSUER
  • profile trusting the current root: connection OK
  • same profile after docker compose down -v && docker compose up --wait: certificate error other than SEC_ERROR_UNKNOWN_ISSUER, while the served chain still verifies with openssl verify against the new root.crt

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant