Project

General

Profile

Actions

Bug #395

closed

TLS cert check only till trusted anchor

Added by Hauke Mehrtens almost 9 years ago. Updated almost 9 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Start date:
05/27/2015
Due date:
% Done:

0%

Estimated time:
Reviewer:
Build Version:

Description

The check of the key sizes should not be done for all certificates provided by the server in the TLS certificates message, but only for the certificates between the server certificate and the certificate in the trust store. You should only check the certificate itself and the intermediate certificates, not the CA cert itself. For example the last certificate at eidpaos.elsteronline.de should not be checked, because your trust store should already contain one the second last certificate. The webservers are sending more certificates then needed because some older browsers are missing the new trusted certificates and the CAs always sign their new CA certificates with their old CA certificates.

A similar problem is in the AusweisApp 1 and it should be fixed in AusweisApp 2.

Actions #1

Updated by Tobias Wich almost 9 years ago

  • Status changed from New to Closed
  • Assignee set to Tobias Wich
  • Target version set to 1.1.0

Fixed in 28755b875

Actions

Also available in: Atom PDF