[138946] in North American Network Operators' Group
Re: The state-level attack on the SSL CA security model
daemon@ATHENA.MIT.EDU (Tony Finch)
Thu Mar 24 10:55:19 2011
Date: Thu, 24 Mar 2011 14:53:42 +0000
From: Tony Finch <dot@dotat.at>
To: Harald Koch <chk@pobox.com>
In-Reply-To: <4D8B5089.4010507@pobox.com>
Cc: NANOG <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Harald Koch <chk@pobox.com> wrote:
>
> This story strikes me as a success - the certs were revoked immediately, and
> it took a surprisingly short amount of time for security fixes to appear all
> over the place.
It would have been much easier if certificate revocation actually worked
properly.
http://www.imperialviolet.org/2011/03/18/revocation.html
Tony.
--
f.anthony.n.finch <dot@dotat.at> http://dotat.at/
Viking, North Utsire, South Utsire: Westerly veering northerly, 4 or 5,
occasionally 6 at first. Moderate or rough. Occasional rain. Moderate or good,
occasionally poor at first.