[NT] SSL Certificate Chain Verification
From: support@securiteam.comDate: 09/23/02
- Previous message: support@securiteam.com: "[EXPL] Remote Exploitable Heap Overflow in Null HTTPd"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Mon, 23 Sep 2002 19:23:09 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
SSL Certificate Chain Verification
------------------------------------------------------------------------
SUMMARY
During SSL/TLS handshake, the web server can optionally send the complete
certificate chain to the client containing its own SERVER-CERT and one or
more CA-CERT(s) with which the signature on SERVER-CERT can be verified.
In some cases, IE6 does not warn the user when the certificate chain sent
by the server is invalid (So far Zoltán tested this only on win2k SP3 and
IE6).
DETAILS
If (one of) the CA-CERT(s) sent by the server is invalid, (e.g., expired),
IE6 first seeks for valid (newer) CA-CERT(s) in its own local repository
(under Trusted Root Certification Authorities and in other lists) and
tries to verify SERVER-CERT with it. If such a "better" CA-CERT was found,
the SSL-handshake continues and the browser does not warn the user.
Note, that this works only if old_ca_public_key == new_ca_public_key AND
issuer_old_ca_cert == issuer_new_ca_cert. Otherwise the signature on
SERVER-CERT would not match, or the issuing CA would not be trusted.
Vendor Status:
Microsoft was notified (9/3/2002), but does not respond.
ADDITIONAL INFORMATION
The information has been provided by
<mailto:Zoltan.Nochta@cooperation-management.de> Zoltán Nochta.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[EXPL] Remote Exploitable Heap Overflow in Null HTTPd"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]