[Noisebridge-discuss] SSL cert blacklisted?

Lamont Lucas lamont at cluepon.com
Wed Oct 29 23:18:58 UTC 2008


Jeff Keyzer wrote:
> Is it just me, or is the SSL cert for the wiki on the SSL blacklist?
>
> http://www.flickr.com/photos/mightyohm/2984629825/ 

Interesting firefox extension.  According to: 
http://codefromthe70s.org/sslblacklist.asp the author thinks that the 
ssl cert was generated on an unpatched debian etch machine that had a 
bogus openSSL build. 

Whoever generated the cert, if you're running debian, you might want to 
check for updates and regenerate any and all ssh/ssl keys and certs made 
in that time.  Otherwise you're running crypto that can be guessed in 
just 98k tries, which takes only a few seconds.





More information about the Noisebridge-discuss mailing list