[Security-Discuss] SSL Certificate problems
Thomas Herlea <Thomas.Herlea-8ZVx2yYfyutX2QMWbMbClIble9XqW/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
Hello, The SSL certificate of download.mandrakeclub.com has expired on "Apr 6 14:08:00 2004 GMT". Please use a valid one, otherwise users will have to override the browser's warning in order to access the web site. That would undermine the efforts spent educating the public about secure online behaviour. There is another reason why the certificate fails the authenticity test: "Certificate signing authority is unknown or invalid". The issuer was not among the SSL Signers known to my browser. I don't know any practical procedure for determining the trustworthiness of a signer and its certificate in the context of such a warning. This decision comes as a distraction from web browsing and is likely to induce users to take the warnings less seriously. One solution involving mainly the "ISTeam" would be to obtain the SSL Certificate from one of the "well-known" Certification Authorities (CAs). MandrakeSoft can solve this problem, at least for Mandrake users, by picking a CA known by default to the browsers which come with the distribution. Another solution involving mainly the "Mandrake Linux Security Team" is for MandrakeSoft to embrace the role of a CA more firmly than in the ad-hoc way it does now (self-signed SSL certificates, various package signing certificates, employee e-mail certificates). Then it could ensured that its CA certificate is distributed with all the browsers it ships and that existing browsers can import it semi-automatically. I think it is a good idea for MandrakeSoft to have a company-wide CA, whether autonomous or certified by a well-known one. By expressing trust in that CA once (even implicitly, by installing Mandrakelinux), users would be shielded from security-related decisions they might not understand. With the greater responsibility entailed by this, MandrakeSoft needs to take good care that the various keys are not misused. Warnings would occur less often, they would be more useful, as they will indicate fraud attempts, and the users would not get desensitised to security warnings. Best regards, Thomas. Standard MandrakeClub member Thomas_Herlea_875. -- [Random fortune cookie]: A Roman divorced from his wife, being highly blamed by his friends, who demanded, "Was she not chaste? Was she not fair? Was she not fruitful?" holding out his shoe, asked them whether it was not new and well made. Yet, added he, none of you can tell where it pinches me. -- Plutarch
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________