Check SSL Certificates for the Vulnerable MD5 Algorithm

From 30th June 2011 Firefox will stop accepting SSL certificates using the MD5 hash. Since January 2009 all SSL certificates purchased from ServerTastic have stopped using the MD5 algorithm. However certificates purchased before this time may still be using MD5.

To check if your SSL certificate is using the MD5 algorithm use the tool below provided by SSLShopper.

Check SSL Certificates for the Vulnerable MD5 Algorithm

If your certificate is affected and it was issued by either RapidSSL, Geotrust, VeriSign or Thawte then you can use the link below to re-issue the certificate free of charge.

Re-issue SSL Certificate

If you have any queries about the MD5 algorithm please see our Support Desk.

Filed under  //  Geotrust   SSL   VeriSign   md5   rapidssl   thawte   vulnerabilities  
Posted by Andy Gambles 

ServerTastic SSL Certificates Safe From Threats Presented at Black Hat

There have been a number of attacks aimed at SSL Certificates demonstrated at the recent Black Hat event in Las Vegas. VeriSign have confirmed that non of the certificates issued within the VeriSign group are susceptibale to these attacks. This includes RapidSSL , thawte and Geotrust.

This was confirmed on Tim Callans SSL Blog. I have pasted the relevent excerpts below

Use of null Characters

The focus of this presentation was various ways to use null characters to fool browsers and other pieces of relying software into believing a certificate has been issued to a different domain than the one to which is was actually issued. The idea is that the attack would give the online criminal the ability to put up a certificate on what appears to be the exact same domain name as the targeted site. sslstrip accomplishes this feat through a Man-in-the-Middle attack and uses the null-character certificate to create its false certificates on the fly.


I'm pleased to say that none of VeriSign's SSL Certificates on any brand allow null characters, meaning that you can't use any of our certificates in the attack detailed today. While the fundamental problem needs to be solved by the client software that trusts these certificates, we still prefer not to be contributing to the problem. And until these problems are solved at the source, EV SSL is a great interim solution. The detailed attack will not work against EV SSL (as agreed by Mr. Marlinspike during the Q and A session after his talk), which means that sites have the power to defend themselves against null character attacks and in fact all attacks using sslstrip.

MD2 No Longer Secure

Kaminsky covered several topics which had SSL as a common theme. Interestingly, he also revealed his own work with null characters, which was very similar to Marlinspike's. In addition, Kaminsky talked about pre-image attacks against MD2, which he expects to be viable this calendar year. He reports that MD2 is not trusted or soon to not be trusted on these applications and platforms: Firefox, OpenSSL, Red Hat, Opera, Apple, Microsoft, Google, and VeriSign. Here I can be more specific. As of May 2009, VeriSign is issuing its SSL Certificates on all brands using SHA-1.

Leading Zeros

Kaminsky also described a "leading zero attack," by which a certificate can fool client software by essentially attaching an invisible zero to the first hex character in the certificate. Again, I'm happy to tell you that VeriSign won't issue SSL Certificates with leading zeros on any of our brands.

Filed under  //  Black Hat   Geotrust   SSL   ServerTastic   VeriSign   rapidssl   security   thawte   vulnerabilities  
Posted by Andy Gambles