How not to run a CA
blog.koehntopp.info
How not to run a CA
1–10 of 255 posts
Re: How not to run a CA
#2Re: How not to run a CA
#3Re: How not to run a CA
#4The thing that isn’t clear to me is how Trustico even had the private keys to begin with. It’s been a while since I’ve purchased a SSL certificate, but I remember generating the private key locally and providing a certificate signing request, which isn’t the private key. What am I misunderstanding here?
But, presumably, Trustco generated the public and private keys for the customers, signed the certificates, and handed the whole mess to the customers. I imagine some customers would even pay a bit more to not have to bother learning to generate a keypair and signing request themselves.
The thing I don't understand is how the CEO thought things would likely work out to his advantage. He must have realized that the person holding all of the cards didn't want to cooperate, and decided to try and bully that person into acting against Trustco's customers. To make such a colossal misjudgement makes me curious what else this CEO has done at previous companies.
Re: How not to run a CA
#5The thing that isn’t clear to me is how Trustico even had the private keys to begin with. It’s been a while since I’ve purchased a SSL certificate, but I remember generating the private key locally and providing a certificate signing request, which isn’t the private key. What am I misunderstanding here?
From my reading of the available data, it would explain why not all of Trustico clients needed their certificates revoked. Some of them will have generated the keys locally, not using Trustico's onlike tool.
Re: How not to run a CA
#6The thing that isn’t clear to me is how Trustico even had the private keys to begin with. It’s been a while since I’ve purchased a SSL certificate, but I remember generating the private key locally and providing a certificate signing request, which isn’t the private key. What am I misunderstanding here?
Maybe they decided preparing CSR is too hard for their clients :/
Re: How not to run a CA
#7SSL is fundamentally broken. Web-of-trust is the only real way to do security.
Re: How not to run a CA
#8You can run arbitrary shell commands as root from their webserver.
Re: How not to run a CA
#9SSL is fundamentally broken. Web-of-trust is the only real way to do security.
Re: How not to run a CA
#10It's either secure or it isn't. Fun fact; Europe's ePrivacy law is coming next year which enforces all communication to be secure.