LWN.net Logo

The case of the fraudulent SSL certificates

The case of the fraudulent SSL certificates

Posted Mar 24, 2011 2:52 UTC (Thu) by ribbo (subscriber, #2400)
Parent article: The case of the fraudulent SSL certificates

I read somewhere that these certificates may have actually been used by a particular country. In the case of the using a CRL or OCSP there's then nothing to stop the MITM from either just redirecting them or blocking access to the service just as they are for the other component of the MITM.


(Log in to post comments)

The case of the fraudulent SSL certificates

Posted Mar 24, 2011 9:37 UTC (Thu) by Thue (subscriber, #14277) [Link]

It is obviously the responsibility of the browser to reject any certificates for which it can't reach the revocation list. Which only Chrome get's partially right: http://www.imperialviolet.org/2011/03/18/revocation.html

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds