Interesting post by Jacob Appelbaum on the compromise of a trusted CA that was used to issue fraudulent certificates:
https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion The discussion shows up (yet again) one of the (several) killer problems of CRL/OCSP-style blacklisting, since you can only blacklist certs that you know that a certificate vending machine has issued, there could be arbitrary numbers of further certs out there that can't be revoked because the vending machine doesn't know that it issued them. Peter. _______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
