Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Microsoft vexed by falsified certs
Kevin Poulsen, SecurityFocus 2001-03-22

Scam artist duped VeriSign into issuing digital certificates under software-maker's name.

Comments Mode:
Blank CDP?? 2001-03-24
S Newton (1 replies)
What is the reason for Verisign leaving the CDP field empty? ...

[ more ]  [ reply ]
CDP has limited value 2001-03-26
Paco Hope <paco (at) tovaris (dot) com [email concealed]>
A CDP would only be useful for downloading a CRL. While that does, sadly, appear to be the state of the art, it is utterly impractical. Imagine the load on the internet if everyone who saw a Verisign certificate downloaded the CRL via an HTTP connection. Some of the CRLs are hundreds of kilobyte...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus