Skip to Content.
Sympa Menu

cacert-sysadm - [Cacert-sysadm] svn.cacert.org uses a compromised ssl key

cacert-sysadm AT lists.cacert.org

Subject: CAcert System Admins discussion list

List archive

[Cacert-sysadm] svn.cacert.org uses a compromised ssl key


Chronological Thread 
  • From: "Christoph A." <casmls AT gmail.com>
  • To: cacert-sysadm AT lists.cacert.org, "Christoph A." <casmls AT gmail.com>
  • Subject: [Cacert-sysadm] svn.cacert.org uses a compromised ssl key
  • Date: Tue, 01 Jul 2008 02:44:54 +0200
  • List-archive: <http://lists.cacert.org/pipermail/cacert-sysadm>
  • List-id: CAcert System Admins discussion list <cacert-sysadm.lists.cacert.org>


I reported that issue some time ago privately to 
support AT cacert.org
 but
did not get any response or reaction. So I'm reporting it here again and
hope the responsible persons are taking care about this and revoke this
certificate _immediately_.

As the subject already says svn.cacert.org is still using a compromised
ssl key. Compromised in the sense that is one of these bad debian keys.

If you want to verify this just go to http://wiki.debian.org/SSLkeys and
look for the chksslkey script or take any other tool available to test
the key against the generated blacklists.

regards,
Christoph A.

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.16.

Top of Page