Users can install SSL Certtificates

From: Steve Mansfield (steve.mansfield_at_PENSAR.CO.UK)
Date: 01/16/04

  • Next message: Daniel Nerenberg: "Windows 2003 security question"
    Date:         Fri, 16 Jan 2004 16:48:41 -0000
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Hi

    I am reliably informed by MS reps that there are no safeguards (ie its
    not preventable by any kind of security / GPO setting etc) on users
    installing SSL Certificates. I have the feeling that this isn't so
    clever.

    Could this be used with the URL obfuscation issue to create a chain of
    'corrupt trust' baring in mind that a certificate is an entry into a
    trust system?

    Regards

    Steve

    -----
    Editor's Note: The 43rd Most Powerful Person in Networking says...

    Out of Office replies to list messages cause you to be unsubscribed automatically. Either subscribe a Public Folder, or ensure your rules are set to ensure list messages are filtered prior to your Out of Office reply. Such automatic replies are a bane to posters, and cause us to have fewer researchers post to NTBugtraq.
    -----


  • Next message: Daniel Nerenberg: "Windows 2003 security question"