Computer Security
[EN] securityvulns.ru
no-pyccku



OpenCA certificate spoofing
Published:17.01.2004
Source:BUGTRAQ
SecurityVulns ID:3374
Type:remote
Level:5/10
Description:A flaw could cause OpenCA to accept a signature from a certificate if the certificate's chain is trusted by the chain directory of OpenCA. This means that a certificate from another PKI can authorize operations on the used PKI if the chain of the used signature certifcate can establish a trust relationship to the actually used PKI.
Original documentdocumentOPENCA, [OpenCA Advisory] Vulnerability in signature verification (17.01.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru