Flaw Endangers Debian-Based Encryption Keys

Discussion in 'other security issues & news' started by ronjor, May 16, 2008.

Thread Status:
Not open for further replies.
  1. tlu

    tlu Guest

    Ocky, snakeoil.pem was the certificate that was also compromised on my system. I found this thread and executed the command mentioned in post #5. This solved the problem, indeed. :) However, I'm still unsure what to do with the unknown validity and unsupported exponent certs. I'll have to do some more research.

    BTW: Marton Anka, the author of SSL Blacklist, answered my question: "The database I use relies on the entire hash values (all 160 bits) plus some extra information such as creating process ID, etc. The published Ubuntu packages only use the first 80 bits of the hash value."
     
  2. Ocky

    Ocky Registered Member

    Joined:
    May 6, 2006
    Posts:
    2,713
    Location:
    George, S.Africa
    I follow in your footsteps as usual. Yes, thanks, snakeoil cert. can now hold
    its head high among its peers in the Not Blacklisted club. :D
    Have set aside about 40 mins. to google for the other stuff, but no luck.

    Regards and :thumb:
     
    Last edited: Jul 10, 2008
  3. Ocky

    Ocky Registered Member

    Joined:
    May 6, 2006
    Posts:
    2,713
    Location:
    George, S.Africa
    I have the exact same output as you, tlu.

    Code:
    Unsupported exponent '/etc/ssl/certs/Entrust.net_Secure_Personal_CA.pem' (skipping)
    Unsupported exponent '/etc/ssl/certs/Entrust.net_Secure_Server_CA.pem' (skipping)
    Unsupported exponent '/etc/ssl/certs/Digital_Signature_Trust_Co._Global_CA_3.pem' (skipping)
    Unsupported exponent '/etc/ssl/certs/Digital_Signature_Trust_Co._Global_CA_1.pem' (skipping)
    Key has unknown validity: /etc/ssl/certs/Verisign_RSA_Secure_Server_CA.pem
    (Wollte schon registrieren, aber bemerkte dass der tlu mir zuvorgekommen ist.) :)
     
  4. tlu

    tlu Guest

    Very frivolous, Ocky, very frivolous! :D

    Yes, exactly the same entries as here. I haven't had enough time lately to do more research but will not give up.

    :D:D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.