fraudulent DigiNotar certificate issuance
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ca-certificates (Debian) |
Fix Released
|
Unknown
|
|||
ca-certificates (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Jamie Strandboge | ||
chromium-browser (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Lucid |
Fix Released
|
Undecided
|
Unassigned | ||
Maverick |
Fix Released
|
Undecided
|
Unassigned | ||
Natty |
Fix Released
|
Undecided
|
Unassigned | ||
Oneiric |
Fix Released
|
Undecided
|
Unassigned | ||
firefox (Ubuntu) |
Fix Released
|
Medium
|
Chris Coulson | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Chris Coulson | ||
nss (Ubuntu) |
Fix Released
|
Medium
|
Micah Gersten | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Micah Gersten | ||
qt4-x11 (Ubuntu) |
Fix Released
|
Medium
|
Didier Roche-Tolomelli | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Didier Roche-Tolomelli | ||
seamonkey (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
Lucid |
Won't Fix
|
Undecided
|
Unassigned | ||
Maverick |
Won't Fix
|
Undecided
|
Unassigned | ||
Natty |
Won't Fix
|
Undecided
|
Unassigned | ||
Oneiric |
Won't Fix
|
Undecided
|
Unassigned | ||
thunderbird (Ubuntu) |
Fix Released
|
Medium
|
Chris Coulson | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Micah Gersten | ||
Oneiric |
Fix Released
|
Medium
|
Chris Coulson | ||
xulrunner-1.9.2 (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Lucid |
Fix Released
|
Medium
|
Micah Gersten | ||
Maverick |
Fix Released
|
Medium
|
Micah Gersten | ||
Natty |
Fix Released
|
Medium
|
Unassigned | ||
Oneiric |
Invalid
|
Medium
|
Unassigned |
Bug Description
USN Information: This is being tracked in USN-1197-*
NOTE: The Firefox update causes a regression for certain Dutch sites which is being tracked in Bug #838322.
NOTE #2: The current update for Thunderbird still shows the DigiNotar Root CA as trusted in the certificate manager. This is due to Thunderbird using the system version of NSS. In this initial update, Thunderbird will actively distrust any certificate signed by the DigiNotar Root CA. Future updates will properly show the root CA as distrusted in the certificate manager.
WORKAROUND (from blog post):
http://
-------
http://
Qt 4.7 blog post: http://
Related branches
visibility: | private → public |
Changed in firefox (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in firefox (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in firefox (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in thunderbird (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in thunderbird (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in thunderbird (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in firefox (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in firefox (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in firefox (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in thunderbird (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in thunderbird (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in thunderbird (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in firefox (Ubuntu Maverick): | |
status: | New → In Progress |
Changed in firefox (Ubuntu Natty): | |
status: | New → In Progress |
Changed in firefox (Ubuntu Oneiric): | |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Maverick): | |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Natty): | |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Oneiric): | |
status: | New → In Progress |
Changed in firefox (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in thunderbird (Ubuntu Oneiric): | |
assignee: | Micah Gersten (micahg) → Chris Coulson (chrisccoulson) |
Changed in firefox (Ubuntu Oneiric): | |
assignee: | Micah Gersten (micahg) → Chris Coulson (chrisccoulson) |
description: | updated |
summary: |
- Fraudulent *.google.com Certificate + fraudulent DigiNotar certificate issuance |
Changed in ca-certificates (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in ca-certificates (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in ca-certificates (Debian): | |
status: | Unknown → Fix Released |
Changed in qt4-x11 (Ubuntu Maverick): | |
status: | New → Invalid |
Changed in qt4-x11 (Ubuntu Natty): | |
status: | New → Invalid |
Changed in qt4-x11 (Ubuntu Oneiric): | |
status: | New → Invalid |
Changed in ca-certificates (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in ca-certificates (Ubuntu Oneiric): | |
assignee: | nobody → Jamie Strandboge (jdstrand) |
Changed in qt4-x11 (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Maverick): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Oneiric): | |
status: | New → Confirmed |
Changed in nss (Ubuntu Lucid): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Maverick): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Natty): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Oneiric): | |
importance: | Undecided → Medium |
Changed in qt4-x11 (Ubuntu Lucid): | |
importance: | Undecided → Medium |
Changed in nss (Ubuntu Lucid): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Maverick): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Natty): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Oneiric): | |
assignee: | nobody → Micah Gersten (micahg) |
Changed in nss (Ubuntu Oneiric): | |
assignee: | Micah Gersten (micahg) → nobody |
Changed in ca-certificates (Ubuntu Lucid): | |
status: | In Progress → Fix Committed |
Changed in ca-certificates (Ubuntu Maverick): | |
status: | In Progress → Fix Committed |
Changed in ca-certificates (Ubuntu Natty): | |
status: | In Progress → Fix Committed |
Changed in nss (Ubuntu Lucid): | |
status: | Confirmed → In Progress |
Changed in nss (Ubuntu Maverick): | |
status: | Confirmed → In Progress |
Changed in nss (Ubuntu Natty): | |
status: | Confirmed → In Progress |
Changed in seamonkey (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in seamonkey (Ubuntu Maverick): | |
status: | New → Confirmed |
Changed in seamonkey (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in seamonkey (Ubuntu Oneiric): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu Maverick): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu Natty): | |
status: | New → Confirmed |
Changed in chromium-browser (Ubuntu): | |
status: | New → Confirmed |
description: | updated |
Changed in ca-certificates (Debian): | |
importance: | Unknown → Undecided |
status: | Fix Released → New |
Changed in ca-certificates (Debian): | |
status: | Unknown → Fix Released |
Changed in chromium-browser (Ubuntu Lucid): | |
status: | Confirmed → Fix Committed |
Changed in chromium-browser (Ubuntu Maverick): | |
status: | Confirmed → Fix Committed |
Changed in chromium-browser (Ubuntu Natty): | |
status: | Confirmed → Fix Committed |
Changed in seamonkey (Ubuntu Lucid): | |
status: | Confirmed → Won't Fix |
Changed in ca-certificates (Ubuntu): | |
assignee: | Jamie Strandboge (jdstrand) → nobody |
This bug was fixed in the package firefox - 7.0~b3+ build1+ nobinonly- 0ubuntu1
--------------- build1+ nobinonly- 0ubuntu1) oneiric; urgency=low
firefox (7.0~b3+
* New upstream release from the beta channel (FIREFOX_ 7_0b3_BUILD1)
- LP: #837557
-- Chris Coulson <email address hidden> Tue, 30 Aug 2011 19:15:51 +0100