Full Disclosure mailing list archives
Re: Creating a rogue CA certificate
From: jlay () slave-tothe-box net
Date: Tue, 30 Dec 2008 13:16:37 -0700 (MST)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SSL/PKI is only as strong as the weakest CA... For those of you who haven't been following this, here you go: http://www.win.tue.nl/hashclash/rogue-ca/ http://www.phreedom.org/research/rogue-ca/md5-collisions-1.0.ppt Enjoy and Happy New Years! elazar -----BEGIN PGP SIGNATURE----- Charset: UTF8 Version: Hush 3.0 Note: This signature can be verified at https://www.hushtools.com/verify wpwEAQECAAYFAklaVFQACgkQi04xwClgpZh4TQP+ODe2/jTHhOrLbKtoSJhZInX+lJXt LMkU/xlYK1Au/f1E5KhXt43uMWYSeC/M0njQRPLyrDfihFlLsmAxGK/97kRQfxEttbcN R0q1BL+WmbiGNglujzSWHqMSkn20r12itVfGP77nEbGYbjidV1BXxFNR2QQwLHZhGLWe gVO/5Zg= =+Pm+ -----END PGP SIGNATURE----- -- Click for free info on getting an MBA, $200K/ year potential. http://tagline.hushmail.com/fc/PnY6qxsZwUN6299xt0fJO8HvJUKovV4hcZ7MH3I6KbhlC0IDsYiG8/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
From Microsoft:
http://www.microsoft.com/technet/security/advisory/961509.mspx "Microsoft is not aware of specific attacks against MD5, so previously issued certificates that were signed using MD5 are not affected and do not need to be revoked. This issue only affects certificates being signed using MD5 after the publication of the attack method." I take it the above is incorrect? James _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Creating a rogue CA certificate, (continued)
- Re: Creating a rogue CA certificate Ureleet (Dec 30)
- Re: Creating a rogue CA certificate Valdis . Kletnieks (Dec 30)
- Re: Creating a rogue CA certificate don bailey (Dec 30)
- Re: Creating a rogue CA certificate n3td3v (Dec 30)
- Re: Creating a rogue CA certificate chort (Dec 30)
- Re: Creating a rogue CA certificate Valdis . Kletnieks (Dec 30)
- Re: Creating a rogue CA certificate chort (Dec 30)
- Re: Creating a rogue CA certificate Valdis . Kletnieks (Dec 30)
- Re: Creating a rogue CA certificate chort (Dec 30)
- Re: Creating a rogue CA certificate Ureleet (Dec 31)
- Re: Creating a rogue CA certificate Valdis . Kletnieks (Dec 30)
- Re: Creating a rogue CA certificate Valdis . Kletnieks (Dec 31)
