Web Hack List

Collected research

CNNINC SSL MitM

Revoking Trust in one CNNIC Intermediate Certificate

An unconstrained intermediate certificate issued by CNNIC was installed in a customer traffic-inspecting firewall, which then generated certificates for domains that operator did not own; browsers accepted them without warning, so any site could be impersonated. Mozilla revoked the intermediate through OneCRL in Firefox 37.

Record

Document
Revoking Trust in one CNNIC Intermediate Certificate
Published by
Mozilla Security Blog
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mozilla Security Blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .