Certificate validation phishing

2017-01-20 Thread tdelmas
Some CA use the following protocol for certificates: - A form ask for a CSR, your contact details (ex. YourName contact@yourdomain ) and the contact details of the person that can validate the website ownership (ex. admin@yourdomain), the email constrained by

RE: Compliance with 7.1.4.2.1 (internal names revocation)

2017-01-20 Thread Steve Medin
Symantec has an additional disclosure regarding internal name certificates valid after October 1. First, we disclose 3 certificates that remained valid after October 1 but expired prior to our previous report. Second, we disclose 3 certificates that were revoked as a result of our analysis but not