The case of the fraudulent SSL certificates
The case of the fraudulent SSL certificates
Posted Mar 24, 2011 18:07 UTC (Thu) by gerv (guest, #3376)Parent article: The case of the fraudulent SSL certificates
"In addition, many browsers do not keep track of the certificates that they have received and alert users when they change." This is true, but the entire point of the certificate model is that this is not necessary. And if it were done, users would be bombarded with cert change errors, because certs change regularly. They would just learn to ignore them.
The two test certificates for which Jacob could find no match in the CRLs were issued to Google and Mozilla to test their blacklisting code.
Gerv
