LWN.net Logo

Fraudulent *.google.com certificate issued

Fraudulent *.google.com certificate issued

Posted Aug 30, 2011 13:30 UTC (Tue) by cesarb (subscriber, #6266)
In reply to: Fraudulent *.google.com certificate issued by lkundrak
Parent article: Fraudulent *.google.com certificate issued

It is the same here in Brazil, see https://bugzilla.mozilla.org/show_bug.cgi?id=438825 (the tax office is https://www.receita.fazenda.gov.br/).

The trick I use is, whenever installing a new computer, go to https://www.mozilla.org/projects/security/certs/pending/, which has both the links to the correct root certificates for ICP-Brasil and their fingerprints (they are what Mozilla will add if/when the CA is accepted). Just click on each one, set the correct trust bits (also listed in that page - in ICP-Brasil's case, it is only "Websites"), compare the fingerprint, and done. Just remember to check you are using https for that page.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds