X.509 weakness?




When I connect to a server using ssh the first time, I get a message
asking
if I really want to connect to this guy.

I replace a server and recycle its IP address, ssh does not want me
connect as the certificate has changed.

So is this a weakness? Say I connect to a server, accept its
certificate and am happy.
Bad guy Garth also snags a copy of the certificate.

The next time I connect to the server, bad guy Garth has changed my
DNS so that
instead of going to the correct server, I go to bad guy Garth's server
who is pretending
to be my server. I look at the CN=www.freesoft.org and say, wow
thats the
server I want and the certificate is good. I am happy.

Am I missing something? Is it possible, by manipulating a DNS server
for a bad
guy to server up a good certificate and have it be undetected by a
client?

-Mike

.



Relevant Pages

  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Configuring LDAP on Entourage 2004 OS X
    ... Microsoft CSS Online Newsgroup Support ... does not work with a self signed SSL certificate OR with the SSL ... configure the System to allow OMA and "Server ActiveSync" access from the ... Configuring Exchange Server 2003 for Client Access. ...
    (microsoft.public.windows.server.sbs)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: Outlook 2003 remote setup
    ... Since I am one of those who said I got it to work the first time, ... So let's say the URL to their server is "abc.tzo.com" ... Click on View Certificate> Install Certificate ... "Greg Howard" wrote in message ...
    (microsoft.public.windows.server.sbs)