Security

VeriSign replaces RapidSSL certificates

by Steve Ragan - Dec 31 2008, 17:06

Talkback

Add your comment (no registration required)

page: 1 

NoNameDec 31st, 2008 - 20:09:29

I checked the signature algorithm of some in some of my certificates and found that Equifax seems to be using MD5... can someone else verify?

Report this comment

EideardJan 1st, 2009 - 04:18:05

What a crock. Tempest in a teapot would be too dynamic for this farce.

Verisign has been making the changeover for a while, now. Banking IT folks I talk to say they stopped used people like RapidSSL exactly because they continued with MD5.

Verisign said weeks ago, they'd have the transition completed by January 2009.

Uh, that's tomorrow.

Report this comment

TipJan 3rd, 2009 - 07:52:09

The attack seems to be mitigated...unless it has already been exploited before (by organized crime or whoever)! In this case, there may already well exist a certificate seemingly signed by RapidSSL and having the rights to certify other certificates. As RapidSSL only signs end server certificates, this means that, in order to (almost - there may also be some rogue end server certificates) fully thwart the attack, it is necessary to modify SSL implementations to refuse certificates with CA rights, signed with RapidSSL.
This phase-in phase-out stuff is just Verisign making fun of us... It was at least possible to reserve the use of MD5 for renewal and not new customers! And how come then did Verisign perform the transition in one day, while the phase-out took them already more than one year (since the theoretical vulnerability was known)???

Report this comment

page: 1 

Add your comment (no registration required)

AddThis Social Bookmark Button

Advertising

Advertising

Advertising

Latest

BitDefender: Trojans amounted for half of threats discovered in June
Q&A: Proginet CIO Kevin Bohan
iPhone 3GS sends AT&T registers into overdrive
Apple revises support document regarding hot 3GS handsets
SingTel confirms iPhone 3GS coming to Singapore

Latest Articles on Monsters&Critics

OAS could suspend Honduras after post-coup leaders balk (Extra)
Nestor-Zimonjic defend Wimbledon doubles title
In Pictures: 'Statue of Liberty's Crown Reopened'
Forman pays tribute to Czech film resilience under communism
 Confusion over Albanian polls over, coalition talks begin
Lady Liberty is reopened to freedom tourists (Roundup)
RESULTS 1ST ADD: Wimbledon Championships
Cancellara wins first Tour stage as Armstrong impresses (Roundup)
Cancellara wins first Tour stage as Armstrong impresses (1st Lead)
Three suspected ETA members arrested in France