LWN.net Logo

25C3: MD5 collisions crack CA certificate (heise online)

25C3: MD5 collisions crack CA certificate (heise online)

Posted Jan 2, 2009 14:15 UTC (Fri) by job (guest, #670)
In reply to: 25C3: MD5 collisions crack CA certificate (heise online) by sitaram
Parent article: 25C3: MD5 collisions crack CA certificate (heise online)

A rogue CA can sign with any algorithm they like. You would have to modify the certificate chaining logic to be safe from this, which would break a large number of legitimate SSL certs.

Please remember that bad advice is worse than no advice.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds