[19945] in bugtraq
Re: Microsoft Security Bulletin MS01-018 -- BAD SIGNATURE?
daemon@ATHENA.MIT.EDU (David Kennedy CISSP)
Fri Mar 30 05:16:15 2001
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Message-ID: <3.0.5.32.20010328230810.036f5c40@pop.fuse.net>
Date: Wed, 28 Mar 2001 23:08:10 -0500
Reply-To: David Kennedy CISSP <david.kennedy@ACM.ORG>
From: David Kennedy CISSP <david.kennedy@ACM.ORG>
X-To: Caskey <caskey@TECHNOCAGE.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <Pine.LNX.4.10.10103280601270.30334-100000@vaio.factory.tci >
-----BEGIN PGP SIGNED MESSAGE-----
At 06:34 AM 3/28/01 -0800, Caskey wrote:
>My questions:
>
>Is this a legitimate advisory?
>
>Does anyone posess a valid, signed copy of this advisory?
>
>Am I being unreasonable in expecting advisories published by
>Microsoft (or any vendor) to be signed? (consistently)
>
>Would the maintainer of the securityfocus archive consider allowing
>access to verifiable copies of the messages in the archive?
>
X-MimeOLE: Produced By Microsoft Exchange V6.0.4418.65
Subject: RE: PGP Signature Failure (again)
Date: Tue, 27 Mar 2001 17:39:55 -0800
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: PGP Signature Failure (again)
Thread-Index: AcC3J8avgEPCRJ1xS3CwLufwMOC+WgAABA0Q
From: "Microsoft Security Response Center" <secure@microsoft.com>
To: "David Kennedy CISSP" <david.kennedy@acm.org>
Cc: "Microsoft Security Response Center" <secure@microsoft.com>
X-OriginalArrivalTime: 28 Mar 2001 01:39:46.0710 (UTC)
FILETIME=[F87FB360:01C0B727]
Hello David,
This is not a certificate issue. There may be an issue with Lsoft or
our
gateways.
The bulletin is definitely valid.
Regards,
Secure@microsoft.com
- -----Original Message-----
From: David Kennedy CISSP [mailto:david.kennedy@acm.org]
Sent: Tuesday, March 27, 2001 5:28 PM
To: Microsoft Security Response Center
Subject: PGP Signature Failure (again)
- -----BEGIN PGP SIGNED MESSAGE-----
At 03:43 PM 3/27/01 -0800, you wrote:
>The following is a Security Bulletin from the Microsoft Product
>Security Notification Service.
>
>Please do not reply to this message, as it was sent from an
>unattended mailbox.
> ********************************
>
>
>*** PGP Signature Status: bad
>*** Signer: Microsoft Security Response Center
><secure@microsoft.com> (Invalid) *** Signed: 3/27/01 6:43:35 PM
>*** Verified: 3/27/01 8:23:50 PM
>*** BEGIN PGP VERIFIED MESSAGE ***
Still having certificate problems.
- -----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.8
Comment: How long has it been since you backed up your hard drive?
iQCVAwUBOsE+DPGfiIQsciJtAQF0ZwP8CifpqF9BR2yutdJRbp3Rhc+s5n5DRuAv
Znxj6nDoMjIXgRkxkscCLnxnhF/G7ZdFsYAUaCU9ZmyB5n2RCh6oDOZnaotN0URa
mVdiZq6byRJesMuoZpBI3jYFudQ8N+cOfuXIYiqDRXSFqd22FCJb6gTDUL06+j/p
gQMUUV1mZnU=
=j/01
- -----END PGP SIGNATURE-----
- --
Regards,
David Kennedy CISSP
Director of Research Services, TruSecure Corp.
http://www.trusecure.com
Protect what you connect. Look both ways before crossing the Net.
-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.8
Comment: I'd upgrade to PGP v7.0.3 if NAI would release one!
iQCVAwUBOsK1J/GfiIQsciJtAQFHYQP/XdEwmJuDd/Z9uUPhU2/HlbstRSHFEZbY
+mpuCYI1HkGOIo6s2z5kB8rqKNjY1tGu2VGMc04Kbft+DxqAQJuQzuo7iXT4pHLv
9kZXzO+zX91Y7wtoaKjnYGFg6M2pMAD9oQJniArQP+B1rFYQP7IXcKdBNnykVpcW
2T8Aoc2d+vg=
=0wTf
-----END PGP SIGNATURE-----
--
Dave Kennedy CISSP Director of Research Services TruSecure Corp.
http://www.trusecure.com