Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 13 May 2015 21:43:59 +0000
From:      Christopher Schulte <christopher@schulte.org>
To:        Paul Franklin <paul.franklin@grg.com>
Cc:        "freebsd-security@freebsd.org" <freebsd-security@freebsd.org>, "james.c.elstone@ntlworld.com" <james.c.elstone@ntlworld.com>
Subject:   Re: Forums.FreeBSD.org - SSL Issue?
Message-ID:  <F90A5645-3C38-4BE5-93D7-483FB68E105A@schulte.org>
In-Reply-To: <CACRVPYOALi-V8D34zeJTYdSwHshYrqtttqVV3=aP8Yb6ZAxfyg@mail.gmail.com>
References:  <CACRVPYOALi-V8D34zeJTYdSwHshYrqtttqVV3=aP8Yb6ZAxfyg@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
> On May 13, 2015, at 9:29 AM, Paul Franklin <paul.franklin@grg.com> wrote:
> 
> Hi James,
> 
> Yes I agree, it looks like the wrong intermediate cert has been used...
> 
> Certificate:
>  Subject: CN=forums.freebsd.org
>  Issuer: CN=Gandi Standard SSL CA 2
> 
> Intermediate:
>  Subject: CN=Gandi Standard SSL CA
> 
> The certificate issuer CN doens't match the intermediate subject CN
> (note the missing 2)

I’ll chime here with a related resource I use from time to time, specifically with regard to website TLS/SSL certs.

First, see:

http://perspectives1.schulte.org:8080/?host=forums.freebsd.org&port=443&service_type=2&;

Which is designed to be used with the Perspectives web browser plugin, allowing supported browsers to query a set of trusted notary servers in real time, comparing the certs (well, actually just the fingerprint of the certs) stored in the notary servers with with the browser sees.  That can be used to potentially detect MITM attacks, even those using trusted-CA-issued certs with would pass the browser’s trust test.

Separate from using it in-line with my web browser to help secure my day-to-day browsing, I from time-to-time also manually query one of my notaries, looking for cert history for a given target site.  In this case, it quickly allowed me to see that a new cert appears to have been installed recently on the forums site, replacing the old one which had been used since October of last year.

It’s a slick tool.  I use it along with other tools that query things like DANE/DNSSEC properties (BTW: thanks, FreeBSD, for publishing signed TLSA records!).

You can see more about my Perspectives setup at https://noc.schulte.org/perspectives.html, which also has a link to the project’s homepage.  You can pull down the server code and setup your own set of trusted servers.  I spread mine out across different networks, improving the chance of detecting malicious activity.

> Regards,
> Paul.

Chris

[-- Attachment #2 --]
0	*H
010	+0	*H
d00lF7;0
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
071014210255Z
221014210255Z010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA0"0
	*H
0
(E,3*
U]"gFSݤ>}m
w鞆FA7~
|-ql"/Q?Vp`G&viĜ73{B'87ds	Nfz1%TII|2o/mD \t	:08VGqǴ3Rp}JTzF;&X}rD Q6L0H0U00U0UUo1ʹk1㬻0U#0N@[i04hCA0i+]0[0'+0http://ocsp.startssl.com/ca00+0$http://aia.startssl.com/certs/ca.crt02U+0)0'%#!http://crl.startssl.com/sfsca.crl0CU <0:08U 000.+"http://www.startssl.com/policy.pdf0
	*H
k}MJ ijtȉ*οR,V!@Yy
Բ ]͒JjY%G?Hyy/0yl%F9F9+9OVq+NhĺoN3TJ!G=SUakuB!k~j
[A#_`_d/Xy[<jY,Z6~0&8p;K0ZTn:eLJKW_Jz}r]R_)PY"ץ!3>˄@vVe2\|ăr
l?-Vm<*
(U-Hf{Ot

t*Pg2ю@:bdٓZ+uZzn07KS*z'O~S=peYB~9_Iq/0D4);	[O(F{4w1W	FMvDmz b0]kmjˮ<jQ00k?{0
	*H
010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA0
131201002714Z
151202171420Z010U
TT9Gd9B4F21h8vSC10	UUS10U	Minnesota10U
Brooklyn Park10UChristopher Schulte1&0$	*H
	christopher@schulte.org0"0
	*H
0
N	ġ}:Aŝ6~ҤP i/;)潕3Ĉ|G$o$
K?[u©-\M0(h;RE:=7pzWglE˖(vZ/y|%DFԫSƩ'[iAԣhVy=K=X2r=mXf!Wʭ1/J@peI_dَ&.'00	U00U0U%0++0Uua(Cl)Xu0U#0Uo1ʹk1㬻0"U0christopher@schulte.org0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 2 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu2-crl.crl0+009+0-http://ocsp.startssl.com/sub/class2/client/ca0B+06http://aia.startssl.com/certs/sub.class2.client.ca.crt0#U0http://www.startssl.com/0
	*H
9u'lԡnW>c^A't`nj"n+cG1z]*8!M#M1%_:u{)=9MHbC!J[y(†ovFEpgk<;lH֒Y\ŗ\_5	331AT1јáa&U Kq2P|qgqcޚ~GAdsW	Մh
1l0h0010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA?{0	+0	*H
	1	*H
0	*H
	1
150513214359Z0#	*H
	1R.kt;0+*0	+710010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA?{0*H
	1010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA?{0
	*H
?,wM1]^%_dt*qD(n**HEXDzGZ?y)LKƆ*:ioM	H7k;lkѨAЄa<Bp1 =-0+뼰_Y'|%PqH앗$,l)
93A
[7"Z_6v;dMT0sڵػGY#+-&THbtQ

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F90A5645-3C38-4BE5-93D7-483FB68E105A>