Push-Nachrichten von MacTechNews.de
Würden Sie gerne aktuelle Nachrichten aus der Apple-Welt direkt über Push-Nachrichten erhalten?
Forum>Software>Game over for DigiNotar: DigiNotar looses their accreditation for qualified certificates

Game over for DigiNotar: DigiNotar looses their accreditation for qualified certificates

sierkb15.09.1123:03
Help Net Security: Is this the end of the line for DigiNotar? :
Help Net Security
DigiNotar is going down quickly and in flames.

After having its SSL and EVSSL certificates deemed untrustworthy by the most popular browsers, around 4200 qualified certificates - i.e. certificates used to create digital signatures - issued by the CA are currently in the process of being revoked and their holders notified of the fact by the Dutch independent post and telecommunication authority (OPTA).

ISC reports that, starting from yesterday, OPTA has terminated the accreditation of DigiNotar as a certificate provider for "qualified" certificates. The revocation of this accreditation also makes DigiNotar unqualified to issue certificates under the PKIoverheid CA.

After having exchanged information with DigiNotar and its auditors, OPTA came to the conclusion that not only has the CA not adhered to the European guidelines and standards governing the issuing of qualified certificates, but has also broken a few local laws.

OPTA's report also finally revealed the auditing firm that missed the rogue Google SSL certificate in July: it's PriceWaterhouseCoopers.

"It’s game over for DigiNotar. Very soon they will officially no longer be a valid entity to issue certificates," commented recently Andrew Storms, Director of Security Operations for nCircle, and it seems that he was right.

ISC Diary: DigiNotar looses their accreditation for qualified certificates


War zu erwarten. Recht so.
0

Kommentare

kix16.09.1114:56
sierkb

War zu erwarten. Recht so.

So ist es!
Und hier ein Artikel auf deutsch

0
ts
ts16.09.1116:44
Leider reicht diese Maßnahme immer noch nicht um SSL wirklich sicher zu machen. Es müssen noch viel mehr CAs weg.
0
minifan1316.09.1117:55
...ist wohl auch peinlich für PriceWaterhouseCoopers...?!
0
Shumweight
Shumweight16.09.1118:18
Aber man sollte schonmal das Diginotar-Zertifikat im Schlüsselbundverwaltungsprogramm löschen.
0

Kommentieren

Diese Diskussion ist bereits mehr als 3 Monate alt und kann daher nicht mehr kommentiert werden.