[Security-Discuss] SSL Certificate problems

Thomas Herlea <Thomas.Herlea-8ZVx2yYfyutX2QMWbMbClIble9XqW/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Hello,

The SSL certificate of download.mandrakeclub.com has expired on "Apr  
6 14:08:00 2004 GMT". Please use a valid one, otherwise users will 
have to override the browser's warning in order to access the web 
site. That would undermine the efforts spent educating the public 
about secure online behaviour.

There is another reason why the certificate fails the authenticity 
test: "Certificate signing authority is unknown or invalid". The 
issuer was not among the SSL Signers known to my browser. I don't 
know any practical procedure for determining the trustworthiness of a 
signer and its certificate in the context of such a warning. This 
decision comes as a distraction from web browsing and is likely to 
induce users to take the warnings less seriously.

One solution involving mainly the "ISTeam" would be to obtain the SSL 
Certificate from one of the "well-known" Certification Authorities 
(CAs). MandrakeSoft can solve this problem, at least for Mandrake 
users, by picking a CA known by default to the browsers which come 
with the distribution.

Another solution involving mainly the "Mandrake Linux Security Team" 
is for MandrakeSoft to embrace the role of a CA more firmly than in 
the ad-hoc way it does now (self-signed SSL certificates, various 
package signing certificates, employee e-mail certificates). Then it 
could ensured that its CA certificate is distributed with all the 
browsers it ships and that existing browsers can import it 
semi-automatically.

I think it is a good idea for MandrakeSoft to have a company-wide CA, 
whether autonomous or certified by a well-known one. By expressing 
trust in that CA once (even implicitly, by installing Mandrakelinux), 
users would be shielded from security-related decisions they might 
not understand. With the greater responsibility entailed by this, 
MandrakeSoft needs to take good care that the various keys are not 
misused. Warnings would occur less often, they would be more useful, 
as they will indicate fraud attempts, and the users would not get 
desensitised to security warnings.

Best regards,
Thomas.
Standard MandrakeClub member Thomas_Herlea_875.
-- 
[Random fortune cookie]:
A Roman divorced from his wife, being highly blamed by his friends, 
who demanded, "Was she not chaste?  Was she not fair?  Was she not 
fruitful?" holding out his shoe, asked them whether it was not new 
and well made. Yet, added he, none of you can tell where it pinches 
me.
		-- Plutarch
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.