Subject: A better approach to security
List archive
- From: Christophe Meessen <christophe AT meessen.net>
- To: A better approach to security <cacert AT lists.cacert.org>
- Subject: Re: [CA cert] [Fwd: [PGPNET] SSL Broken?]
- Date: Mon, 05 Jan 2009 09:22:47 +0100
Christoph A. a écrit :
Jan Pieter Cornet wrote:
It's rather hard for end-users to detect
these certificates (if not impossible)
SSL Blacklist now detects and warns about certificate chains that use
the MD5 algorithm for RSA signatures.
http://www.codefromthe70s.org/sslblacklist.asp
If I understood correctly, the problem is the generation of forged certificates with the same MD5 as a genuine certificate by exploiting MD5 collisions. Setting the CA flag in this forged certificate allows to sign other certificates on behalf of the rootCA.
So every certificat signed by its CA with the MD5 hash (or MD2 !!) is suspect.
It should be enough to get rid of the rootCA using MD5, MD2 or worse to secure oneself because the chain of certification will be cut at the root. Any certificate deriving from those will be flagged as unverifiable. Looking at the rootCA certificat details, there is a field telling the hash algorithm used for signing. So it should be easy to recongnize the one using unsecure hash.
Is that assumption valid ?
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Jan Pieter Cornet, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Jan Pieter Cornet, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christoph A., 01/04/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], John W. Moore III, 01/05/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/05/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], Alain Knaff, 01/05/2009
-
Re: [CA cert] SSL Broken?,
Bernhard Froehlich, 01/05/2009
- Re: [CA cert] SSL Broken?, Alain Knaff, 01/05/2009
- Re: [CA cert] SSL Broken?, Bernhard Froehlich, 01/05/2009
- Re: [CA cert] SSL Broken?, Philipp Guehring, 01/05/2009
- Re: [CA cert] SSL Broken?, Christophe Meessen, 01/05/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], Philipp Guehring, 01/05/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christoph A., 01/04/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Jan Pieter Cornet, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/03/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], Philipp Guehring, 01/04/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Jan Pieter Cornet, 01/03/2009
Archive powered by MHonArc 2.6.24.