Skip to Content.
Sympa Menu

cacert-sysadm - Re: [Cacert-sysadm] svn.cacert.org uses a compromised ssl key

cacert-sysadm AT lists.cacert.org

Subject: CAcert System Admins discussion list

List archive

Re: [Cacert-sysadm] svn.cacert.org uses a compromised ssl key


Chronological Thread 
  • From: Philipp Gühring <pg AT futureware.at>
  • To: cacert-sysadm AT lists.cacert.org
  • Subject: Re: [Cacert-sysadm] svn.cacert.org uses a compromised ssl key
  • Date: Sun, 6 Jul 2008 18:36:32 +0200
  • List-archive: <http://lists.cacert.org/pipermail/cacert-sysadm>
  • List-id: CAcert System Admins discussion list <cacert-sysadm.lists.cacert.org>
  • Organization: Futureware 2001

Hi,

> I reported that issue some time ago privately to 
> support AT cacert.org
>  but
> did not get any response or reaction. So I'm reporting it here again and
> hope the responsible persons are taking care about this and revoke this
> certificate _immediately_.
>
> As the subject already says svn.cacert.org is still using a compromised
> ssl key. Compromised in the sense that is one of these bad debian keys.
>
> If you want to verify this just go to http://wiki.debian.org/SSLkeys and
> look for the chksslkey script or take any other tool available to test
> the key against the generated blacklists.

Thanks for the report. A new key has been generated, a new certificate has 
been issued, and the old certificate has been revoked.

Best regards,
Philipp Gühring





Archive powered by MHonArc 2.6.16.

Top of Page