The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Newsgroups: linux.debian.bugs.dist
From: Daniel Kahn Gillmor <d...@fifthhorseman.net>
Date: Sat, 21 Feb 2009 20:20:07 +0100
Local: Sat, Feb 21 2009 2:20 pm
Subject: Bug#514807: a proposal for consideration for V1 CA certs in Etch (and Lenny?)
On 02/21/2009 04:16 AM, Andreas Metzler wrote: > On 2009-02-19 Daniel Kahn Gillmor <d...@fifthhorseman.net> wrote: I believe gnutls-cli (appropriately) sets >> I've done a bit of research on this bug (dealing with V1 CA certificates >> for gnutls in etch and/or lenny), and i do think that it is potentially >> quite serious. >> For example, the certificate used by https://mail.google.com/ appears to > Shouldn't gnutls-cli mark the certificate as unverified in that case? GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT, because the semantics of its invocation indicate that the certificates passed to the trusted store are explicitly limited to CA certificates, and cannot possibly be end-entity certificates. > ametzler@argenau:/etc/ssl/certs$ gnutls-cli --x509cafile /etc/ssl/certs/Verisign_Class_3_Public_Primary_Certification_Authority.pem -p https mail.google.com Your invocation told gnutls-cli that the certificate *was* a CA, so it > Processed 1 CA certificate(s). didn't have to guess whether you'd intended to use the attached certificate as an end-entity certificate or not. > cu and- mystified -reas Hope this helps de-mystify somewhat. Frankly, the V1 vs. V3 business seems to me to be as much a problem with the GnuTLS API as it does with the crusty old X.509v1 specification. If GnuTLS certificate validation were to use two different user-provided lists of certificates: one of explicit CAs and one of potential peers (End Entities), this whole discussion would be moot. But of course, that's not what it does: applications provide the hth, --dkg
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| |||||||||||||||||