CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

SSL Certificate - Revoked

2018年9月13日 1642点热度 0人点赞 0条评论

漏洞类别:General remote services

漏洞等级: 

漏洞信息

An SSL certificate associates an entity (person, organization, host, etc.) with a public key. In an SSL connection a client authenticates the remote server using the server's certificate and extracts the public key in the certificate to establish the secure connection.

SSL certificates can be revoked by the issuing certificate authority. The revocation status of a certificate can be obtained from certificate revocation lists issued by the certificate authority, by performing OCSP (Online Certificate Status Protocol) queries against the certificate authority's OCSP server, or, from OCSP Stapling information provided by the server that presents the certificate.

漏洞危害

Using a revoked certificate is considered unsafe and prohibited by some SSL clients. The reason for a certificate to be revoked is often a suspected security breach involving the certificate or its associated private key. Continued use of the certificate after such an event may allow an attacker to perform a man-in-the-middle attack.

解决方案

Please install a server certificate that has not been revoked.

0daybank

标签: 暂无
最后更新:2018年9月19日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me