{"id":520145,"date":"2010-04-08T04:15:59","date_gmt":"2010-04-08T08:15:59","guid":{"rendered":"http:\/\/techie-buzz.com\/?p=22588"},"modified":"2010-04-27T10:06:43","modified_gmt":"2010-04-27T14:06:43","slug":"rsa-security-1024-v3-the-unclaimed-root-certificate-mayhem-in-firefox","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/520145","title":{"rendered":"RSA Security 1024 V3: The Unclaimed Root Certificate Mayhem in Firefox"},"content":{"rendered":"<p>Mozilla security saw a new <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=549701\">bug-report filed at bugzilla<\/a> reporting an unclaimed RSA root certificate. The certificate goes by the name of RSA Security 1024 V3. Both Verisign and RSA have declined ownership of this certificate.<\/p>\n<p><a href=\"http:\/\/www.linkedin.com\/pub\/kathleen-wilson\/0\/914\/9b6\">Kathleen Wilson<\/a>, an active Consultant at Mozilla Corporation has been actively digging through Mozilla security issues. He writes at this Mozilla security Google group saying,<\/p>\n<blockquote>\n<p>I propose that the &#8220;RSA Security 1024 V3&#8243; root certificate authority be<br \/>\nremoved from NSS.<\/p>\n<p>OU = RSA Security 1024 V3<br \/>\nO = RSA Security Inc<br \/>\nValid From: 2\/22\/01<br \/>\nValid To: 2\/22\/26<br \/>\nSHA1 Fingerprint:<br \/>\n3C:BB:5D:E0:FC:D6:39:7C:05:88:E5:66:97:BD:46:2A:BD:F9:5C:76<\/p>\n<p>I have not been able to find the current owner of this root. Both RSA<br \/>\nand VeriSign have stated in email that they do not own this root.<\/p>\n<\/blockquote>\n<p>This issue got everyone worried about this being a rouge certificate. However, later Wilson assured the certificate&#8217;s origin by saying,<\/p>\n<blockquote>\n<p>I have received email from official representatives of RSA confirming<br \/>\nthat RSA did indeed create the &#8220;RSA Security 1024 V3&#8243; root certificate<br \/>\nthat is currently included in NSS (Netscape\/Mozilla) and also in Apple&#8217;s<br \/>\nroot cert store.<\/p>\n<\/blockquote>\n<p>He also added that that RSA has since, dropped the root certificate and so should Mozilla. In another mail from RSA, it was told that the private key for this root was safe with RSA. This assures that this flaw was not exploited and now the certificate will be removed from NSS (Network Security Services).<\/p>\n<p>[ Via: <a href=\"http:\/\/linuxtoday.com\/news_story.php3?ltsn=2010-04-08-001-35-NW-NT\">LinuxToday<\/a> ]<\/p>\n<div style=\"font-size:12px\">\n<strong>Share:<\/strong><br \/>\n<a href=\"http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html#commentrespond\" rel=\"bookmark\" >Comment on This Post<\/a> |<br \/>\n<a href=\"http:\/\/twitter.com\/home?source=techiebuzz&#038;status=RSA%20Security%201024%20V3:%20The%20Unclaimed%20Root%20Certificate%20Mayhem%20in%20Firefox%20http%3A%2F%2Fbit.ly%2F913g6g%20via%20@techiebuzzer\" rel=\"bookmark\" >Tweet This<\/a> |<br \/>\n<a href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html\" rel=\"bookmark\" >Share on Facebook<\/a> |<br \/>\n<a href=\"http:\/\/del.icio.us\/post?url=http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html&#038;title=RSA%20Security%201024%20V3:%20The%20Unclaimed%20Root%20Certificate%20Mayhem%20in%20Firefox\" rel=\"bookmark\" >Save to Delicious<\/a> |<br \/>\n<a href=\"http:\/\/www.stumbleupon.com\/submit?url=http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html\" rel=\"bookmark\" >Stumble This<\/a> |<br \/>\n<a href=\"http:\/\/digg.com\/submit?phase=2&#038;url=http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html&#038;title=RSA%20Security%201024%20V3:%20The%20Unclaimed%20Root%20Certificate%20Mayhem%20in%20Firefox\" rel=\"bookmark\" >Digg This<\/a> |<br \/>\n<a href=\"http:\/\/www.reddit.com\/submit?url=http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html&#038;title=RSA%20Security%201024%20V3:%20The%20Unclaimed%20Root%20Certificate%20Mayhem%20in%20Firefox\" rel=\"bookmark\" >Reddit This<\/a>\n<\/div>\n<p><\/p>\n<div><strong style=\"font-size:11px;\">TAGS:<\/strong> <span style=\"text-transform:uppercase;font-size:11px;\"><a href=\"http:\/\/techie-buzz.com\/tag\/bugzilla\" rel=\"tag\">bugzilla<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/mozilla\" rel=\"tag\">Mozilla<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/rsa\" rel=\"tag\">RSA<\/a><\/span><br \/>\n<\/small><\/div>\n<div>\n<br \/>\n<font size=\"4\"><strong>Announcement:<\/strong> Missing Mobile News in the Main RSS Feed? We have decided to remove the mobile content from the main feed, please subscribe to our dedicated <a href=\"http:\/\/go.techie-buzz.com\/mobilerssanch\" >Mobile News RSS Feed<\/a> at <a href=\"http:\/\/go.techie-buzz.com\/mobilerss\" >http:\/\/feeds.techie-buzz.com\/techiemobile<\/a>. Thank you for your understanding.<\/font><\/p>\n<\/div>\n<div style=\"background:#E1E1E1; border: dotted 1px; padding:5px; margin-top:5px;font-size:11px\">\n<a href=\"http:\/\/techie-buzz.com\/browsers\/rsa-security-unclaimed-root-certificate-firefox.html\" title=\"RSA Security 1024 V3: The Unclaimed Root Certificate Mayhem in Firefox\">RSA Security 1024 V3: The Unclaimed Root Certificate Mayhem in Firefox<\/a> originally appeared on <a href=\"http:\/\/techie-buzz.com\" title=\"Techie Buzz\">Techie Buzz<\/a> written by Chinmoy Kanjilal on Thursday 8th April 2010 04:15:59 AM. Please read the <a href=\"http:\/\/techie-buzz.com\/terms-of-use\">Terms of Use<\/a> for fair usage guidance. <\/div>\n<p><\/p>\n<h2>Don&#8217;t miss these Related Posts:<\/h2>\n<ul>\n<li><a href=\"http:\/\/techie-buzz.com\/firefox\/firefox-352-fixes-critical-vulnerabilities.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Firefox 3.5.2 Now Available For Downloads, Fixes Critical Security Issues<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/browsers\/firefox-3-6-2-released-fixes-security-vulnerability.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Firefox 3.6.2 Released, Fixes Security Vulnerability<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/browsers\/firefox-3-6-3-patches-pwn2own-flaw.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Firefox 3.6.3 Patches Pwn2Own Flaw, Back to Security<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/firefox\/firefox-3-6-2-security-vulnerability.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Firefox 3.6.2 Candidate Fixes Critical Security Vulnerability<\/a><\/li>\n<\/ul>\n<h2>Join Techie Buzz on Your Favorite Social Networking Sites<\/h2>\n<ul>\n<li><a href=\"http:\/\/go.techie-buzz.com\/facebookfanrss\" title=\"Become a Techie Buzz fan on Facebook\">Become a Techie Buzz fan on Facebook<\/a><\/li>\n<li><a href=\"http:\/\/go.techie-buzz.com\/twitterrss\" title=\"Follow Techie Buzz on Twitter\">Follow Techie Buzz on Twitter<\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/gk7hEl0RfKrhcqna9eCCTmWVS_M\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/gk7hEl0RfKrhcqna9eCCTmWVS_M\/0\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/gk7hEl0RfKrhcqna9eCCTmWVS_M\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/gk7hEl0RfKrhcqna9eCCTmWVS_M\/1\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/techiebuzz\/~4\/1ynLuvJ2H1k\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mozilla security saw a new bug-report filed at bugzilla reporting an unclaimed RSA root certificate. The certificate goes by the name of RSA Security 1024 V3. Both Verisign and RSA have declined ownership of this certificate. Kathleen Wilson, an active Consultant at Mozilla Corporation has been actively digging through Mozilla security issues. He writes at [&hellip;]<\/p>\n","protected":false},"author":1821,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-520145","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/520145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1821"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=520145"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/520145\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=520145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=520145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=520145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}