Bug 751366

Summary: Revoking Trust in DigiCert Sdn. Bhd Intermediate Certificate Authority from nss
Product: [Other] Security Response Reporter: Huzaifa S. Sidhpurwala <huzaifas>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: emaldona, jorton
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-11-10 06:43:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 751369, 751370, 751371, 751674, 752280, 752282    
Bug Blocks: 751368    

Description Huzaifa S. Sidhpurwala 2011-11-04 14:11:28 UTC
Entrust, Inc., a certificate authority in Mozilla’s root program, informed the mozilla project that that one of their subordinate CAs, the Malaysian company DigiCert Sdn. Bhd, has issued 22 certificates with weak keys. 

References:
http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/
https://bugzilla.mozilla.org/show_bug.cgi?id=698753

Comment 2 Huzaifa S. Sidhpurwala 2011-11-07 05:53:56 UTC
Created nss tracking bugs for this issue

Affects: fedora-all [bug 751674]

Comment 5 errata-xmlrpc 2011-11-09 13:17:15 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2011:1444 https://rhn.redhat.com/errata/RHSA-2011-1444.html

Comment 6 Huzaifa S. Sidhpurwala 2011-11-10 06:43:37 UTC
This issue does not affect the version of ca-certificates package shipped with Red Hat Enterprise since the affected certificate is not shipped by the package.

This issue does not affect the version of ca-certificates package shipped with Fedora-14, Fedora-15 and Fedora-16, since the affected certificate is not shipped by the package.