LWN.net Logo

how about browser warnings?

how about browser warnings?

Posted Jun 24, 2008 11:59 UTC (Tue) by pdundas (subscriber, #15203)
Parent article: SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

If checking the revocation list is too hard, how about browsers checking certificates for the
vulnerability? 

It might be helpful for browsers to display a "weak certificate" warning for affected certs
signed by a recognised authority (such as "this site uses a weak certificate which could allow
them to be impersonated). Worried customers contacting site owners could well encourage them
to upgrade to a more secure cert.

If there is no recognised CA, there is not much point in such a warning - in this case an
impersonator could just issue their own certificate claiming to be the target - and I guess
this case is already covered by an appropriate warning.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds