LWN.net Logo

CAcert certs aren't "invalid"

CAcert certs aren't "invalid"

Posted Nov 19, 2009 10:45 UTC (Thu) by dwmw2 (subscriber, #2063)
Parent article: TLS renegotiation vulnerability

The resiprocate.org certificate isn't really invalid — it's just that it's signed by CAcert, and you probably don't have the CAcert root CA installed on your system. It's not included in Firefox by default, unfortunately.


(Log in to post comments)

CAcert certs aren't "invalid"

Posted Nov 19, 2009 13:29 UTC (Thu) by meuh (subscriber, #22042) [Link]

It's reported as invalid because CACert Root Certificate use MD5 signature, which is known to be broken.

Using plug-in for Firefox like SSL black List will tell you more about this : http://codefromthe70s.org/sslblacklist.aspx .

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds