Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

Debian OpenSSL vulnerability - major CAs unaffected

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


a.klink at cynops

May 15, 2008, 5:10 AM

Post #1 of 1 (150 views)
Permalink
Debian OpenSSL vulnerability - major CAs unaffected

Hi,

some good news in the whole Debian OpenSSL vulnerability mess:
We have tested all the CAs with 1024 and 2048 bit keys with a
public exponent of 653537 which are included in the
Windows or Mozilla CA store against our list of known weak keys,
but none of them were affected.
Not that we expected that they were, but we thought it might be better
to check ;-)
A minor 13% has not been tested because they were using different
key lengths or public exponents ...

Cheers,
Alex
--
Dipl.-Math. Alexander Klink | IT-Security Engineer | a.klink[at]cynops.de
mobile: +49 (0)178 2121703 | Cynops GmbH | http://www.cynops.de
----------------------------+----------------------+---------------------
HRB 7833, Amtsgericht | USt-Id: DE 213094986 | Geschäftsführer:
Bad Homburg v. d. Höhe | | Martin Bartosch

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.