|
|
|
|
|
by _wmd
2652 days ago
|
|
This seems highly unlikely to be authoritative -- AIUI serial number unpredictability is critical to SSL certificate security, as without it, it becomes possible to induce a CA into producing a signature that matches a certificate for another domain. Unless something else changed about the format when the hash algorithm was changed, AFAIK this property is independent to the hash algorithm in use If memory serves it isn't a theoretical attack either, I read about it used against (Startcom maybe?) not so many years ago |
|