Category Archives: Information

General news/information to the CAcert community or about security in general

Google on improving certificate security

Benl writes: Improving SSL certificate security

Friday, April 1, 2011 9:05 AM Posted by Ben Laurie, Google Security Team

In the wake of the recent [incident], there has been a great deal of speculation about how to improve the public key infrastructure, on which the security of the Internet rests. Unfortunately, this isn’t a problem that will be fixed overnight. Luckily, however, [engineers] have long known about these issues and have been devising solutions for some time.

Given the current interest it seems like a good time to talk about two projects in which Google is engaged.

The first is the Google Certificate Catalog. Google’s web crawlers scan the web on a regular basis in order to provide our search and other services. In the process, we also keep a record of all the SSL certificates we see. The Google Certificate Catalog is a database of all of those certificates, published in DNS. So, for example, if you wanted to see what we think of https://www.google.com/’s certificate, you could do this:

[tech details snipped]

The second initiative to discuss is the DANE Working Group at the IETF. DANE stands for DNS-based Authentication of Named Entities. In short, the idea is to allow domain operators to publish information about SSL certificates used on their hosts. It should be possible, using DANE DNS records, to specify particular certificates which are valid, or CAs that are allowed to sign certificates for those hosts. So, once more, if a certificate is seen that isn’t consistent with the DANE records, it should be treated with suspicion. Related to the DANE effort is the individually contributed CAA record, which predates the DANE WG and provides similar functionality.

[caveats snipped]

Improving the public key infrastructure of the web is a big task and one that’s going to require the cooperation of many parties to be widely effective. We hope these projects will help point us in the right direction.

CATS login bug fixed (bug#889)

If you tried to log in to CATS recently with a newly created certificate you probably failed. Especially when using a Class 3 certificate. Now I hope this bug is finally fixed.

Like usual for such bugs it was quite a trivial thing, for details compare CAcert/Education/CATS/login.php in svn with its previous version.

For analysis: certificates affected contained a serial number wich started with a non-digit character after stripping learing zeros. So Class 3 certificates with serial number bigger than 09:ff (issued since about half a year ago) and Class 1 certificates with serial greater than 09:ff:ff (issued since recently) have been affected.

I’m still waiting for the first explicit confirmation of someone now able to log in, but the analysis nicely fits the symtoms and the problem could be reproduced on the test system, so I hope we finally got it.

CAcert assurances at Linux Infotag Augsburg

This year too, there will be enough 35-point assurers at the booth of the LUG Ottobrunn at Linux Infotag in Augsburg (26th march) to get fully assured (100 points). Check for the CAcert badges & logo !

Auch dieses Jahr werden ausreichend 35-Punkte Assurer am Stand der LUG Ottobrunn beim Linux Infotag in Augsburg (26. März) anwesend sein, um voll assured zu werden (100 Punkte). Folgt dem CAcert Logo !

ATE-Munich, 2. April

After Munich’s ATE in 2009 another one is scheduled. This time it is a joint offer from the CAcert community and Munich’s open source meetings. It is also supported by secure-u e.V.
We will host the ATE on afternoon of 2nd April. More details on the wiki.

There are a couple of options to indicate that you are attending:

– Email I will attend ATE-Munich
– Acknowledge the XING event
– Edit the wiki directly

As IanG said: “The ATE or Assurer Training Event is exceptionally recommended for all Assurers, and include parts which contribute directly to our audit. Come and find out how you can also contribute.”

München

~ 30 people have been registered already. Looking forward to seeing you at the ATE.

And the Oscar goes to …

… CAcert4München.

Hmmm, not really, to be honest 😉

It is true that it has been awarded. But it didn’t won the Oscar, not even the „Goldene Kamera“.
CAcert4München was amongst the awarded proposals for the Munich Open Government Day (MOGDy) .

And the award can be viewed at the bottom of this page.

What is the proposal about ?

Well, in a nutshell it suggests that the Munich Government uses CAcert for client and server certificates needed. And they might include CAcert’s root certificates into their own Linux distribution called LiMux.

Note that one can vote for the proposal still. The more people support the proposal the more important it looks to the people running the MOGDy campaign.

How to support ?

Register: Go to the registration page , upper righ hand corner ? Registrieren.

Then on the right hand side fill in:

Benutzername: user name, your choice
E-Mail: your email address
Passwort: choose your own password
Passwort (bestätigen): enter your password a second time

Vote: Go to the proposal page and on the upper left hand side either click on
dafür (aye) or
dagegen (naye)

Of course MOGDy is targeted (but not restricted) to people living in Munich.
So please support the proposal, since it is an advantage for Munich (save costs, create yet more attractiveness in the open source community) and for CAcert (probably one „big shot“ for the inclusion status).

Thanks
Frank

Workaround for Russian Translation of the CAcert Website (bug #900)

Russia Translation of CAcert.org WebsiteWe had received a couple of reports by either irc, emails to support or on mailing lists, that the Russian Translation of our CAcert.org Website has garbled Russian translations. This has been reported as Bug #900.

After several analyzes, tests, discussions, we came to the conclusion, that we need an overall UTF-8 upgrade of the critical system. This has to be started as an individual project. As this project doesn’t effects our great efforts on Audit, the priority is lowered against several other Audit essential projects. So currently, there is no easy and no quick fix possible. So we, or better to say Michael V. A. (one of the bug reporters) worked out an workaround:

the exact steps to reproduce both the problem and the workaround:

1. The Bug
http://CAcert.org [^] / Translations / ???????
( http://www.cacert.org/index.php?id=0&lang=ru_RU )

Now the text is garbled (“Western ISO-8859-1” autodetected).

2. The Workaround
Switching to ISO-8859-5.

In my browser (Firefox 3.6.13) it’s exactly the following:

View / Character Encoding / More Encodings
/ East European / Cyrillic (ISO-8859-5)

Now all Russian text is okay.
The workaround works for me.
Yes, I think this should work for other users, as well.

CAcert at Fosdem 11th, Feb 5th – 6th 2011

FOSDEM, the Free and Open Source Software Developers' European Meeting

CAcert and sidux e.V. will be present at Fosdem 2011, the Free and Open Source Software Developers’ European Meeting, February Sat 5th and Sun 6th 2011

If you want to help on our booth, register yourself on our events wiki page Fosdem 2011 planning

CU at Fosdem ….

ATE-Brisbane

ATE-Brisbane is happening! Francois has scheduled us into Linux Conference Australia’s annual bash in Brisbane‘s QUT Garden Point Campus. We will host an ATE on afternoon of 24th January. More details on the wiki.

I will attend ATE-Brisbane! Registration is essential as you won’t be able to get in.

For those who can’t make the afternoon timeslot, I’ll be available on Sunday evening. Mail as above if you want an additional ATE or just assurances & help.

The ATE or Assurer Training Event is exceptionally recommended for all Assurers, and include parts which contribute directly to our audit. Come and find out how you can also contribute. Please RSVP as above.

Other events in Oz are welcome! Mail us with suggestions (use the RSVP above). Note the board has earmarked funds to get us to Melbourne and Brisbane, and also some travel budget to other NSW locations (Wollongong and Newcastle, but hey, there are other places)! If you can offer us a venue, we’re interested!

CAcert webserver downtime on Wednesday December 29, 2010

We have scheduled to perform a system software upgrade of the CAcert webserver on Wednesday December 29 2010, starting at 10:00 CET. The upgrade will last at most until 13:00 CET, but we are aiming to complete well before that time. During the upgrade, the CAcert webserver will be unavailable for all users, and no certificates can be signed or revoked. All other CAcert servers will remain up and running though (including OCSP and CRL services).

Wytze van der Raay
team leader CAcert ciritical system administrators