Bug 751366 - Revoking Trust in DigiCert Sdn. Bhd Intermediate Certificate Authority from nss
Summary: Revoking Trust in DigiCert Sdn. Bhd Intermediate Certificate Authority from nss
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 751369 751370 751371 751674 752280 752282
Blocks: 751368
TreeView+ depends on / blocked
 
Reported: 2011-11-04 14:11 UTC by Huzaifa S. Sidhpurwala
Modified: 2019-09-29 12:48 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-11-10 06:43:37 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1444 0 normal SHIPPED_LIVE Important: nss security update 2011-11-09 18:14:43 UTC

Description Huzaifa S. Sidhpurwala 2011-11-04 14:11:28 UTC
Entrust, Inc., a certificate authority in Mozilla’s root program, informed the mozilla project that that one of their subordinate CAs, the Malaysian company DigiCert Sdn. Bhd, has issued 22 certificates with weak keys. 

References:
http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/
https://bugzilla.mozilla.org/show_bug.cgi?id=698753

Comment 2 Huzaifa S. Sidhpurwala 2011-11-07 05:53:56 UTC
Created nss tracking bugs for this issue

Affects: fedora-all [bug 751674]

Comment 5 errata-xmlrpc 2011-11-09 13:17:15 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2011:1444 https://rhn.redhat.com/errata/RHSA-2011-1444.html

Comment 6 Huzaifa S. Sidhpurwala 2011-11-10 06:43:37 UTC
This issue does not affect the version of ca-certificates package shipped with Red Hat Enterprise since the affected certificate is not shipped by the package.

This issue does not affect the version of ca-certificates package shipped with Fedora-14, Fedora-15 and Fedora-16, since the affected certificate is not shipped by the package.


Note You need to log in before you can comment on or make changes to this bug.