In association with heise online

6 October 2009, 18:41

Worth Reading: Certificate Request? Ask Later!

Moxie Marlinspike has taken a closer look at the Online Certificate Status Protocol (OCSP) that is the primary revocation mechanism for SSL certificates. OCSP is used when a browser wants to query whether a certificate has been revoked. Marlinspike discovered that the included status messages sent in response to this query are not digitally signed. So while it is not possible to simply fake the answer to the query, if a certificate is still valid a man-in-the-middle could modify the status. If the value of OCSPResponseStatus is set to 3, the requesting browser will interpret that as "Try again Later" and will accept the certificate temporarily.

See also:

(djwm)

  • Share this article
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit




The H open source

The H Security

The H Internet Toolkit