LWN.net Logo

Really a business problem

Really a business problem

Posted Jan 3, 2009 9:03 UTC (Sat) by rks (guest, #55908)
In reply to: Really a business problem by job
Parent article: 25C3: MD5 collisions crack CA certificate (heise online)

Another fundamental problem: SSL is only as secure as the private key of the certificate key pair.

So the CA certifies that the private key was known to some entity at some time. If the key gets compromised (without revocation), too bad. The certificate is now worthless. Even worse, now it creates a false sense of security.

How many sysdmins will take the trouble to create a new certificate after a site was broken into, and also revoke the old certificate?


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds