Date: Wed, 13 May 2015 21:43:59 +0000 From: Christopher Schulte <christopher@schulte.org> To: Paul Franklin <paul.franklin@grg.com> Cc: "freebsd-security@freebsd.org" <freebsd-security@freebsd.org>, "james.c.elstone@ntlworld.com" <james.c.elstone@ntlworld.com> Subject: Re: Forums.FreeBSD.org - SSL Issue? Message-ID: <F90A5645-3C38-4BE5-93D7-483FB68E105A@schulte.org> In-Reply-To: <CACRVPYOALi-V8D34zeJTYdSwHshYrqtttqVV3=aP8Yb6ZAxfyg@mail.gmail.com> References: <CACRVPYOALi-V8D34zeJTYdSwHshYrqtttqVV3=aP8Yb6ZAxfyg@mail.gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] > On May 13, 2015, at 9:29 AM, Paul Franklin <paul.franklin@grg.com> wrote: > > Hi James, > > Yes I agree, it looks like the wrong intermediate cert has been used... > > Certificate: > Subject: CN=forums.freebsd.org > Issuer: CN=Gandi Standard SSL CA 2 > > Intermediate: > Subject: CN=Gandi Standard SSL CA > > The certificate issuer CN doens't match the intermediate subject CN > (note the missing 2) I’ll chime here with a related resource I use from time to time, specifically with regard to website TLS/SSL certs. First, see: http://perspectives1.schulte.org:8080/?host=forums.freebsd.org&port=443&service_type=2& Which is designed to be used with the Perspectives web browser plugin, allowing supported browsers to query a set of trusted notary servers in real time, comparing the certs (well, actually just the fingerprint of the certs) stored in the notary servers with with the browser sees. That can be used to potentially detect MITM attacks, even those using trusted-CA-issued certs with would pass the browser’s trust test. Separate from using it in-line with my web browser to help secure my day-to-day browsing, I from time-to-time also manually query one of my notaries, looking for cert history for a given target site. In this case, it quickly allowed me to see that a new cert appears to have been installed recently on the forums site, replacing the old one which had been used since October of last year. It’s a slick tool. I use it along with other tools that query things like DANE/DNSSEC properties (BTW: thanks, FreeBSD, for publishing signed TLSA records!). You can see more about my Perspectives setup at https://noc.schulte.org/perspectives.html, which also has a link to the project’s homepage. You can pull down the server code and setup your own set of trusted servers. I spread mine out across different networks, improving the chance of detecting malicious activity. > Regards, > Paul. Chris [-- Attachment #2 --] 0 *H 010 + 0 *H d00lF7;0 *H 0}10 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0 071014210255Z 221014210255Z010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA0"0 *H 0 (E,3* U]"gFSݤ>}m w鞆FA7~ |-ql"/Q?Vp`G&viĜ73{B'87ds Nfz1%TII|2o/mD \t :08VGqǴ3Rp}JTzF;&X}rD Q6 L0H0U0 0U0UUo1ʹk1㬻0U#0N@[i04hCA0i+]0[0'+0http://ocsp.startssl.com/ca00+0$http://aia.startssl.com/certs/ca.crt02U+0)0'%#!http://crl.startssl.com/sfsca.crl0CU <0:08U 000.+"http://www.startssl.com/policy.pdf0 *H k}MJ ijtȉ*οR,V!@Yy Բ ]͒JjY%G?Hyy/0yl%F9F9+9OVq+NhĺoN3TJ!G=SUakuB!k~j [A#_`_d/Xy[<jY, Z6~0&8p;K0ZTn:eLJKW_Jz}r]R_)PY"ץ!3>˄@vVe2\|ăr l?-Vm<* (U-Hf{Ot t*Pg2ю@:bdٓZ+uZzn07KS*z'O~S=peYB~9_Iq/0D4); [O(F{4w1W FMvDmz b0]kmjˮ<jQ00k?{0 *H 010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA0 131201002714Z 151202171420Z010U TT9Gd9B4F21h8vSC10 UUS10U Minnesota10U Brooklyn Park10UChristopher Schulte1&0$ *H christopher@schulte.org0"0 *H 0 N ġ}:Aŝ6~ҤP i/;)潕3Ĉ|G$o$ K?[u©-\M0(h;RE:=7pzWglE˖(vZ/y|%DFԫSƩ'[iAԣhVy=K=X2r=mXf!Wʭ1/J@peI_dَ&.' 00 U0 0U0U%0++0Uua(Cl)Xu0U#0Uo1ʹk1㬻0"U0christopher@schulte.org0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 2 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu2-crl.crl0+009+0-http://ocsp.startssl.com/sub/class2/client/ca0B+06http://aia.startssl.com/certs/sub.class2.client.ca.crt0#U0http://www.startssl.com/0 *H 9u'lԡ nW>c^A't`nj"n+cG1z]*8!M#M1%_:u{)=9MHbC!J[y(ovFEpgk<;lH֒Y\ŗ\_5 331AT1јáa&U Kq2P|qgqcޚ~GAdsW Մh 1l0h0010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA?{0 + 0 *H 1 *H 0 *H 1 150513214359Z0# *H 1R.kt;0+*0 +710010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA?{0*H 1010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 2 Primary Intermediate Client CA?{0 *H ?,wM1]^%_dt*qD(n**HEX DzGZ?y)LKƆ*:ioM H7k;lkѨAЄa<Bp1 =-0+뼰_Y'|%PqH앗$,l) 93A [7"Z_6v;dMT0sڵػGY#+-&THbtQ
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F90A5645-3C38-4BE5-93D7-483FB68E105A>
