Re: D-Trust certificates with ROCA fingerprints

2017-10-19 Thread Enrico Entschew via dev-security-policy
Hi all, a list of certificates showing a ROCA fingerprint was posted by Rob Stradling at Mozilla.dev.security.policy on 2017/10/18 available at https://misissued.com/batch/28/ This contains among other certificates a number of D-Trust related certificates that all show a ROCA fingerprint. A

Incident Report D-Trust certificates with ROCA fingerprints

2017-10-19 Thread Kim Nguyen via dev-security-policy
Incident Report D-Trust certificates with ROCA fingerprints A list of certificates showing a ROCA fingerprint was posted by Rob Stradling at Mozilla.dev.security.policy on 2017/10/18 available at https://misissued.com/batch/28/ This contains among other certificates a number of D-Trust related

Re: ROCA fingerprints found on crt.sh (was Re: Efficient test for weak RSA keys generated in Infineon TPMs / smartcards)

2017-10-19 Thread Erwann Abalea via dev-security-policy
Le mercredi 18 octobre 2017 11:15:03 UTC+2, Rob Stradling a écrit : > I've completed a full scan of the crt.sh DB, which found 171 certs with > ROCA fingerprints. > > The list is at https://misissued.com/batch/28/ > > Many of these are Qualified/EUTL certs rather than anything to do with > the

Re: ROCA fingerprints found on crt.sh (was Re: Efficient test for weak RSA keys generated in Infineon TPMs / smartcards)

2017-10-19 Thread Nick Lamb via dev-security-policy
On Wednesday, 18 October 2017 10:15:03 UTC+1, Rob Stradling wrote: > I've completed a full scan of the crt.sh DB, which found 171 certs with > ROCA fingerprints. > > The list is at https://misissued.com/batch/28/ > > Many of these are Qualified/EUTL certs rather than anything to do with > the