Anyone know a way to remove DigiNotar as a system root CA in OS X? I spent a few minutes struggling with Keychain to no avail, and couldn't Google my way to useful help.
I have un-trusted the Chinese CNNIC two operating system versions ago (10.5), and it is still set to the same setting. This seems less fragile than deleting the cert to me.
What's to keep an OS upgrade from restoring the certificate?
A system or user-maintained blacklist seems like a more tenable solution. You don't want to delete the cert, you want to hang a scarlet letter on it. Oh, and not trust it for anything (or better, use it to blacklist any site that attempts to use it).
At least for me there's no such choice as delete in the System Roots keychain.
The only thing I can do is to set it to "never trust" and still Chrome/Safari show it as trusted: http://imgur.com/NcUYf