RSA Security 1024 V3: The Unclaimed Root Certificate Mayhem in Firefox

Mozilla security saw a new bug-report filed at bugzilla reporting an unclaimed RSA root certificate. The certificate goes by the name of RSA Security 1024 V3. Both Verisign and RSA have declined ownership of this certificate.

Kathleen Wilson, an active Consultant at Mozilla Corporation has been actively digging through Mozilla security issues. He writes at this Mozilla security Google group saying,

I propose that the “RSA Security 1024 V3″ root certificate authority be
removed from NSS.

OU = RSA Security 1024 V3
O = RSA Security Inc
Valid From: 2/22/01
Valid To: 2/22/26
SHA1 Fingerprint:
3C:BB:5D:E0:FC:D6:39:7C:05:88:E5:66:97:BD:46:2A:BD:F9:5C:76

I have not been able to find the current owner of this root. Both RSA
and VeriSign have stated in email that they do not own this root.

This issue got everyone worried about this being a rouge certificate. However, later Wilson assured the certificate’s origin by saying,

I have received email from official representatives of RSA confirming
that RSA did indeed create the “RSA Security 1024 V3″ root certificate
that is currently included in NSS (Netscape/Mozilla) and also in Apple’s
root cert store.

He also added that that RSA has since, dropped the root certificate and so should Mozilla. In another mail from RSA, it was told that the private key for this root was safe with RSA. This assures that this flaw was not exploited and now the certificate will be removed from NSS (Network Security Services).

[ Via: LinuxToday ]

Share:
Comment on This Post |
Tweet This |
Share on Facebook |
Save to Delicious |
Stumble This |
Digg This |
Reddit This

TAGS: , ,

Announcement: Missing Mobile News in the Main RSS Feed? We have decided to remove the mobile content from the main feed, please subscribe to our dedicated Mobile News RSS Feed at http://feeds.techie-buzz.com/techiemobile. Thank you for your understanding.

RSA Security 1024 V3: The Unclaimed Root Certificate Mayhem in Firefox originally appeared on Techie Buzz written by Chinmoy Kanjilal on Thursday 8th April 2010 04:15:59 AM. Please read the Terms of Use for fair usage guidance.

Don’t miss these Related Posts:

Join Techie Buzz on Your Favorite Social Networking Sites