• Search Blog Archives

Follow us: 
Like us on Facebook Follow us on Twitter Visit us on YouTube Follow us on LinkedIn

DigiNotar CA compromise
Posted: 30 Aug 2011 10:53 AM

SSL certificates are used to validate the identity of a website to users. Over the weekend, it was found that DigiNotar, a Dutch Certificate Authority, had issued a rogue SSL certificate for *.google.com. Today, this was confirmed by DigiNotar in a press release.

 

According to DigiNotar's own investigation, they found out that they were compromised on July 19, 2011, and several rogue SSL certificates had been issued including the one to *.google.com. All the other ones were revoked, but for some reason, DigiNotar missed revoking the one issued for Google's domain. Why is this important? With the rogue certificate issued by a trusted CA, it's possible to do Man-in-the-Middle attacks and listen in to any traffic going to Google's services, such as Google Mail, Google Docs, Google Plus, and Google Apps, without any visible warnings to users.

 

Websense products

 

If you have SSL Inspection enabled in Websense Web Security Gateway (Anywhere) solutions and have the Certificate Validation Engine enabled, you will already have the revoked certificates downloaded and installed.

 

If you want to follow Microsoft and Firefox and disable trust for DigiNotar's Root CA, we do offer that option as well.

  1. Open up the Administration UI for Websense Content Gateway (https://123.123.123.123:8081 by default)
  2. Go to Configure -> SSL -> Certificates
  3. Scroll down and select DigiNotar Root CA and "Click to change status to Deny"

 

Filed under:

Patrik Runald

Comments

  Chris Scott said on Monday, September 26, 2011 3:18 PM

This is not enough, we'd like to block certs signed by Diginotar. I believe the above steps will only cause the user to get a certificate warning, which many users ignore. Is there a way to block the certs?

  Patrik Runald Websense Security Labs Blogger said on Thursday, September 29, 2011 10:38 AM

You also have to have the Certificate Validation enabled, otherwise the block won't take effect. But if that's enabled the Websense Security Gateway will block any access to sites using certificates sign by the blocked CA.



Leave a Comment

(required) 

Email address: (required) 
 
  
 


©2013 Websense, Inc. All Rights Reserved.