[SSL Observatory] DigiNotar Certificate Hierarchy

Peter Gutmann pgut001 at cs.auckland.ac.nz
Tue Sep 6 03:44:52 PDT 2011


Gervase Markham <gerv at mozilla.org> writes:

>I am attempting to chart the DigiNotar certificate hierarchy in a public
>document, so Mozilla can be sure that our current block is sufficiently wide.

In case you haven't seen the Comodo, possibly Diginotar, and now StartSSL,
Globalsign, and several others hacker's post:

  http://pastebin.com/1AxH30em

you may need to get ready to block a whole lot more than just Diginotar in the
near future.  Unlike Diginotar, we're now getting into the TB2F CAs, so the
response will be interesting...

Peter.




More information about the Observatory mailing list