[47385] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Exponent 3 damage spreads...

daemon@ATHENA.MIT.EDU (Erik Tews)
Thu Sep 28 09:27:58 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: Erik Tews <erik@debian.franken.de>
To: Philipp =?ISO-8859-1?Q?G=FChring?= <pg@futureware.at>
Cc: cryptography@metzdowd.com
In-Reply-To: <200609250128.36232.pg@futureware.at>
Date: Tue, 26 Sep 2006 07:35:12 +0200


--=-4gM0VLFtuSnP9nE/2Epz
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Am Montag, den 25.09.2006, 01:28 +0200 schrieb Philipp G=FChring:
> Hi,
>=20
> We have been researching, which vendors were generating Exponent 3 keys, =
and=20
> we found the following until now:
>=20
> * Cisco 3000 VPN Concentrator
> * CSP11
> * AN.ON / JAP (they told me they would change it on the next day)
> (perhaps more to come)
>=20
> My current estimate is that 0.26% of the certificates in the wild have=20
> Exponents <=3D17

I did a little survey one month ago for my bsc. thesis.

I found out, that round about 1.19% of all https-server-certs use an
exponent <=3D 17. I did choose round about 32,000 random webservers for
this survey.

What is intresting is what happens when it comes to imap-ssl. Here, only
0.1% of all servers use a server-cert with exponent <=3D 17. Imap-ssl
users seem to be the better ssl-users, tls 1.0 is more widespread there,
small rsa-modulus-sizes are more seldom, and ssl 2.0 is not so common
there too.

I will publish some more details later.

--=-4gM0VLFtuSnP9nE/2Epz
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: Dies ist ein digital signierter Nachrichtenteil

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQBFGLwQ1V7s4RB7CAcRAnDJAJ4229kcsULutHTfBwp5ouUnNH8S7QCfVLAZ
Y3gdusYDza7SE4vzrBX64Ug=
=m9yR
-----END PGP SIGNATURE-----

--=-4gM0VLFtuSnP9nE/2Epz--


---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post