Subject: A better approach to security
List archive
- From: Christophe Meessen <christophe AT meessen.net>
- To: A better approach to security <cacert AT lists.cacert.org>
- Subject: Re: [CA cert] SSL Broken?
- Date: Mon, 05 Jan 2009 10:49:11 +0100
Philipp Guehring a écrit :
Hi,Thank you very much. I missed that piece of information.
If MD5 is crackedNo.
Unfortunately, there are various attack-vectors, and MD5 only fell for
one of them yet.
so that collistions can be constructedYes, at the moment, you have to construct both sides of the collissions.
...
No. It might be worthless, it might be worth something. The problem isIn terms of certification it is worthless because the validity is uncertain and there is no safe and efficient mean to ask the CA.
that by only looking at the certificates, you can't know whether they
are worthless or not. You would have to ask the CA, whether they
actually issued that certificate, or not.
It looks like MD5 signed certificates have to be discarded.
Regarding self signed certificates using MD5 or MD2 I wouldn't assume them to be safe. The possibility to generate an MD5 collision with a given MD5 value may be around the corner, if not already feasible but not known to the public.
It is the right time for a new and stronger hash algorithm.
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?]
, (continued)
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Jan Pieter Cornet, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christoph A., 01/04/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], John W. Moore III, 01/05/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/05/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], Alain Knaff, 01/05/2009
-
Re: [CA cert] SSL Broken?,
Bernhard Froehlich, 01/05/2009
- Re: [CA cert] SSL Broken?, Alain Knaff, 01/05/2009
- Re: [CA cert] SSL Broken?, Bernhard Froehlich, 01/05/2009
- Re: [CA cert] SSL Broken?, Philipp Guehring, 01/05/2009
- Re: [CA cert] SSL Broken?, Christophe Meessen, 01/05/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], Philipp Guehring, 01/05/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christoph A., 01/04/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Jan Pieter Cornet, 01/03/2009
-
Re: [CA cert] [Fwd: [PGPNET] SSL Broken?],
Christophe Meessen, 01/03/2009
- Re: [CA cert] [Fwd: [PGPNET] SSL Broken?], Philipp Guehring, 01/04/2009
Archive powered by MHonArc 2.6.24.