SSL security with server certificate compromised



Hello everyone,

This may be very obvious, but I would love to hear a clear explanation.

Let's say I configure a web server with HTTPS only. Then I issue a
couple of queries from a browser, while I sniff all the traffic out to
a file (even though is is encrypted). Finally, I hand you the sniffed
traffic AND the server certificate file (cert file, key file, even the
key phrase or password). Questions:

1. Can the sniffed traffic be decrypted, at least in theory, with all
the information in the scenario I am posing? My guess is "yes",
although I am not sure how to go about it.
2. If the traffic can be decrypted, is this a time consuming process,
or a pretty quick thing? Perhaps it is even trivially scriptable?

Thanks for any information and comments. Best regards.

Gonzalo Diethelm

.



Relevant Pages

  • Re: Problems with SSL accessw through a web browser
    ... when I try access to imaps through a web server using a ... if you enter a password when generating the key file, ... need to type that password in every time you restart apache (ie: ...
    (Fedora)
  • RE: SSL and BizTalk?
    ... When making an HTTPS connection to an SSL secured web server the only thing ... SSL cert on the web server. ... If you open Internet Explorer on the BizTalk machine and try browsing to ...
    (microsoft.public.biztalk.general)
  • IIS 6 conflict using port 443 for NON-SSL traffic
    ... I need IIS to respond to HTTP requests on port 443 for different IPs on the ... HTTPS traffic. ... Here is an example of what I am trying to do: On Web Server "A" I need to ...
    (microsoft.public.inetserver.iis.security)
  • This is not it, was: Re: $_POST is empty (in MSIE?)
    ... Could https be a problem, in a way that it sometimes "eats" up POST data? ... if the Web server closes the initial connection request. ... hints: ...
    (comp.lang.php)
  • Re: credit card software for Linux???
    ... The CyberCash people have a Linux SDK you can download. ... or Perl scripts to perform https type connections to their credit card ... connection to a https server. ... through my virtual store front using Quick Commerce's secure web server, ...
    (comp.os.linux.misc)