|
|
|
|
|
by londons_explore
2523 days ago
|
|
On one hand, this incident was a massive amount of work by probably thousands of people to replace all the revoked certificates. Certificates which are perfectly good for communication and do not pose any significant security risk. On the other hand, allowing a CA to violate the BR's without pain will just encourage others to do so. |
|
Is it so? I remember that in 2008 someone was able to create a rouge CA certificate because of the predictability of serial numbers[1]. It was a different time: we still used md5, but are you sure the limited entropy used to generate serial numbers does not pose any security risk?
[1]https://www.win.tue.nl/hashclash/rogue-ca/