[19945] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Microsoft Security Bulletin MS01-018 -- BAD SIGNATURE?

daemon@ATHENA.MIT.EDU (David Kennedy CISSP)
Fri Mar 30 05:16:15 2001

Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Message-ID:  <3.0.5.32.20010328230810.036f5c40@pop.fuse.net>
Date:         Wed, 28 Mar 2001 23:08:10 -0500
Reply-To: David Kennedy CISSP <david.kennedy@ACM.ORG>
From: David Kennedy CISSP <david.kennedy@ACM.ORG>
X-To:         Caskey <caskey@TECHNOCAGE.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <Pine.LNX.4.10.10103280601270.30334-100000@vaio.factory.tci >

-----BEGIN PGP SIGNED MESSAGE-----

At 06:34 AM 3/28/01 -0800, Caskey wrote:
>My questions:
>
>Is this a legitimate advisory?
>
>Does anyone posess a valid, signed copy of this advisory?
>
>Am I being unreasonable in expecting advisories published by
>Microsoft (or any vendor) to be signed? (consistently)
>
>Would the maintainer of the securityfocus archive consider allowing
>access to verifiable copies of the messages in the archive?
>

X-MimeOLE: Produced By Microsoft Exchange V6.0.4418.65
Subject: RE: PGP Signature Failure (again)
Date: Tue, 27 Mar 2001 17:39:55 -0800
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: PGP Signature Failure (again)
Thread-Index: AcC3J8avgEPCRJ1xS3CwLufwMOC+WgAABA0Q
From: "Microsoft Security Response Center" <secure@microsoft.com>
To: "David Kennedy CISSP" <david.kennedy@acm.org>
Cc: "Microsoft Security Response Center" <secure@microsoft.com>
X-OriginalArrivalTime: 28 Mar 2001 01:39:46.0710 (UTC)
FILETIME=[F87FB360:01C0B727]

Hello David,

This is not a certificate issue. There may be an issue with Lsoft or
our
gateways.

The bulletin is definitely valid.

Regards,
Secure@microsoft.com

- -----Original Message-----
From: David Kennedy CISSP [mailto:david.kennedy@acm.org]
Sent: Tuesday, March 27, 2001 5:28 PM
To: Microsoft Security Response Center
Subject: PGP Signature Failure (again)


- -----BEGIN PGP SIGNED MESSAGE-----

At 03:43 PM 3/27/01 -0800, you wrote:
>The following is a Security  Bulletin from the Microsoft Product
>Security Notification Service.
>
>Please do not  reply to this message,  as it was sent  from an
>unattended mailbox.
>                    ********************************
>
>
>*** PGP Signature Status: bad
>*** Signer: Microsoft Security Response Center
><secure@microsoft.com>  (Invalid) *** Signed: 3/27/01 6:43:35 PM
>*** Verified: 3/27/01 8:23:50 PM
>*** BEGIN PGP VERIFIED MESSAGE ***


Still having certificate problems.


- -----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.8
Comment: How long has it been since you backed up your hard drive?

iQCVAwUBOsE+DPGfiIQsciJtAQF0ZwP8CifpqF9BR2yutdJRbp3Rhc+s5n5DRuAv
Znxj6nDoMjIXgRkxkscCLnxnhF/G7ZdFsYAUaCU9ZmyB5n2RCh6oDOZnaotN0URa
mVdiZq6byRJesMuoZpBI3jYFudQ8N+cOfuXIYiqDRXSFqd22FCJb6gTDUL06+j/p
gQMUUV1mZnU=
=j/01
- -----END PGP SIGNATURE-----

- --
Regards,

David Kennedy CISSP
Director of Research Services, TruSecure Corp.
http://www.trusecure.com
Protect what you connect. Look both ways before crossing the Net.


-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.8
Comment: I'd upgrade to PGP v7.0.3 if NAI would release one!

iQCVAwUBOsK1J/GfiIQsciJtAQFHYQP/XdEwmJuDd/Z9uUPhU2/HlbstRSHFEZbY
+mpuCYI1HkGOIo6s2z5kB8rqKNjY1tGu2VGMc04Kbft+DxqAQJuQzuo7iXT4pHLv
9kZXzO+zX91Y7wtoaKjnYGFg6M2pMAD9oQJniArQP+B1rFYQP7IXcKdBNnykVpcW
2T8Aoc2d+vg=
=0wTf
-----END PGP SIGNATURE-----

--
Dave Kennedy CISSP Director of Research Services TruSecure Corp.
http://www.trusecure.com

home help back first fref pref prev next nref lref last post