View Single Post
  #1 (permalink)  
Old 12-22-2006, 12:06 PM
Gonzo
Guest
 
Posts: n/a
Default SSL security with server certificate compromised

Hello everyone,

This may be very obvious, but I would love to hear a clear explanation.

Let's say I configure a web server with HTTPS only. Then I issue a
couple of queries from a browser, while I sniff all the traffic out to
a file (even though is is encrypted). Finally, I hand you the sniffed
traffic AND the server certificate file (cert file, key file, even the
key phrase or password). Questions:

1. Can the sniffed traffic be decrypted, at least in theory, with all
the information in the scenario I am posing? My guess is "yes",
although I am not sure how to go about it.
2. If the traffic can be decrypted, is this a time consuming process,
or a pretty quick thing? Perhaps it is even trivially scriptable?

Thanks for any information and comments. Best regards.

Gonzalo Diethelm


Reply With Quote