I know MD5 was broken ages ago but this article expands on the theme -
make your own legitimate-looking root CA:
http://www.crunchgear.com/2008/12/30/md5-collision-creates-rogue-certificate-authority/
--
Thomas Hruska
Shining Light Productions
Home of BMP2AVI, Nuclear Vision, ProtoNova, and Win32 OpenSSL.
http://www.slproweb.com/
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List openssl-users@openssl.org
Automated List Manager majord...@openssl.org