Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Security team successfully cracks SSL using 200 PS3's and MD5flaw.

  • From: Steven M. Bellovin
  • Date: Fri Jan 02 12:06:56 2009

On Fri, 2 Jan 2009 17:53:55 +0100
"Terje Bless" <link@pobox.com> wrote:

> On Fri, Jan 2, 2009 at 5:44 PM,  <Valdis.Kletnieks@vt.edu> wrote:
> > Hmm... so basically all deployed FireFox and IE either don't even
> > try to do a CRL, or they ask the dodgy certificate "Who can I ask
> > if you're dodgy?"
> 
> Hmm. Don't the shipped-with-the-browser trusted root certificates
> include a CRL URL?
> 
> 
Every CA runs its own CRL server -- it has to be that way.


		--Steve Bellovin, http://www.cs.columbia.edu/~smb





Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.