MS 03-041 and SSL Certificates

From: Mullins, Walter A. (wmullins_at_STONEPIGMAN.COM)
Date: 10/22/03

  • Next message: Farrington, Ryan: "MS03-045 superseed"
    Date:         Wed, 22 Oct 2003 15:36:21 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    After installing the 03-041 patch, users began receiving messages that SSL
    certificates were issued by an untrusted sources. This message occurred
    even when the certificates in question were issued by a CA on the trusted
    list. After uninstalling 03-041, the messages no longer occurred and the
    certificates were accepted without user intervention.

    This occurred on workstations running NT 4.0 Workstation sp 6 with both IE
    5.5 sp2 10/2003 security patch and IE 6.0 sp1 10/2003 security patch.

    Anyone else seen the same behavior?

    Walter Mullins
    Stone Pigman

    -----
    Marcus Ranum's new book "The Myth of Homeland Security" is now out and
    is available from http://www.amazon.com/ranum In this hard-hitting
    review of the homeland security business, Ranum shows us how the problem
    is vastly harder than it's being made to sound, and how special
    interests, *** covering, and bureaucracy are threatening to derail any
    chance of making progress.
    -----


  • Next message: Farrington, Ryan: "MS03-045 superseed"
  • Quantcast