LWN.net Logo

SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

Posted Jun 18, 2008 20:06 UTC (Wed) by ewen (subscriber, #4772)
In reply to: SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft) by endecotp
Parent article: SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

Interestingly just yesterday I got an email from Comodo about a weak SSL certificate advising
how to get it reissued for free.  (Which was a useful email because the certificate is on a
system that wasn't vulnerable, but it turns out the key material had been created on a
vulnerable system.)  

They're also apparently going to add the vulnerable certificates to their revocation list
soon.  Although as you say I'm not sure how widely those revocation lists are checked by
applications.

Ewen



(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds