Bug 6609 - Add randomess to GS-CA signed certificates
: Add randomess to GS-CA signed certificates
Status: ASSIGNED
: GridShib
GridShib-CA
: 0.5
: All All
: P3 enhancement
: ---
Assigned To:
:
:
:
:
  Show dependency treegraph
 
Reported: 2009-01-02 08:36 by
Modified: 2009-12-17 20:53 (History)


Attachments


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2009-01-02 08:36:21
Adding randomness to the serial numbers of GS-CA signed certificates would
mitigate threats posed by current MD5 attacks (and other hash algorithms in the
future).
------- Comment #1 From 2009-12-17 20:52:38 -------
See Bug 6614 for details.
------- Comment #2 From 2009-12-17 20:53:48 -------
I'm removing this as a blocker from 2.0 as it is, in my judgment, not a big
security risk at this time.