Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-11-2011, 09:51 AM
kathy
Guest
 
Posts: n/a
Default Security certificates for all my browsers

Would Microsoft's updates to a PC's certificates also work for my non-
Microsoft browsers?

I don't know exactly how certificates work except that there is some
hierarchy of trusted certificate providers.

As I understand it sometimes there are oversights in checking in which
certificate providers got authorized, so updates have to be downloaded by
PCs to let the PC know the latest list of trusted certificates.

I run XP and Microsoft's updater provides me with updates to security
certificates.

My question is ....... would Microsoft's updates to a PC's certificates
also work for my non-Microsoft browsers?

I run Chrome, Firefox and Opera. Do I need to do update their certificates
individually or would the Microsoft update also be used by them?

Reply With Quote
  #2 (permalink)  
Old 11-11-2011, 01:32 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Security certificates for all my browsers

From: "kathy" <nospam@mail.invalid>

> Would Microsoft's updates to a PC's certificates also work for my non-
> Microsoft browsers?
>
> I don't know exactly how certificates work except that there is some
> hierarchy of trusted certificate providers.
>
> As I understand it sometimes there are oversights in checking in which
> certificate providers got authorized, so updates have to be downloaded by
> PCs to let the PC know the latest list of trusted certificates.
>
> I run XP and Microsoft's updater provides me with updates to security
> certificates.
>
> My question is ....... would Microsoft's updates to a PC's certificates
> also work for my non-Microsoft browsers?
>
> I run Chrome, Firefox and Opera. Do I need to do update their certificates
> individually or would the Microsoft update also be used by them?


Is this in reference to DigiCert Sdn. Bhd issuing certificates with weak encryption keys?
If it is Mozilla and Google have release updates.

I don't know about the rest of the Browsers and if they use the Microsoft Certifcate Store
where Microsft released an update.

--
Dave
Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
  #3 (permalink)  
Old 11-11-2011, 05:23 PM
VanguardLH
Guest
 
Posts: n/a
Default Re: Security certificates for all my browsers

kathy wrote:

> Would Microsoft's updates to a PC's certificates also work for my non-
> Microsoft browsers?
>
> I don't know exactly how certificates work except that there is some
> hierarchy of trusted certificate providers.
>
> As I understand it sometimes there are oversights in checking in which
> certificate providers got authorized, so updates have to be downloaded by
> PCs to let the PC know the latest list of trusted certificates.
>
> I run XP and Microsoft's updater provides me with updates to security
> certificates.
>
> My question is ....... would Microsoft's updates to a PC's certificates
> also work for my non-Microsoft browsers?
>
> I run Chrome, Firefox and Opera. Do I need to do update their certificates
> individually or would the Microsoft update also be used by them?


What Microsoft updates did you get that have certificates for PCs?
Certificates are for sites, not for hosts and not for any particular web
browser. Are you running a web server where you need a certificate (if
you're using authenticated logins or using SSL connects to your web
server)?

Since you don't know what they are, you don't need them.

Reply With Quote
  #4 (permalink)  
Old 11-11-2011, 05:25 PM
Doug McIntyre
Guest
 
Posts: n/a
Default Re: Security certificates for all my browsers

kathy <nospam@mail.invalid> writes:
>I run XP and Microsoft's updater provides me with updates to security
>certificates.


>My question is ....... would Microsoft's updates to a PC's certificates
>also work for my non-Microsoft browsers?


>I run Chrome, Firefox and Opera. Do I need to do update their certificates
>individually or would the Microsoft update also be used by them?


It depends on the browser and version, but generally not.

A few alternative browsers did use the Microsoft CryptoAPI at some
point in time, but most (if not all?) now use their own security
certificate database, and would need to be patched separately.

I wouldn't trust any of them to have updated along Microsoft's patch,
and you'll need separate patches for each.


Reply With Quote
  #5 (permalink)  
Old 11-11-2011, 08:48 PM
Barry Margolin
Guest
 
Posts: n/a
Default Re: Security certificates for all my browsers

In article <j9jp6v$4ua$1@news.albasani.net>, VanguardLH <V@nguard.LH>
wrote:

> kathy wrote:
>
> > Would Microsoft's updates to a PC's certificates also work for my non-
> > Microsoft browsers?
> >
> > I don't know exactly how certificates work except that there is some
> > hierarchy of trusted certificate providers.
> >
> > As I understand it sometimes there are oversights in checking in which
> > certificate providers got authorized, so updates have to be downloaded by
> > PCs to let the PC know the latest list of trusted certificates.
> >
> > I run XP and Microsoft's updater provides me with updates to security
> > certificates.
> >
> > My question is ....... would Microsoft's updates to a PC's certificates
> > also work for my non-Microsoft browsers?
> >
> > I run Chrome, Firefox and Opera. Do I need to do update their certificates
> > individually or would the Microsoft update also be used by them?

>
> What Microsoft updates did you get that have certificates for PCs?
> Certificates are for sites, not for hosts and not for any particular web
> browser. Are you running a web server where you need a certificate (if
> you're using authenticated logins or using SSL connects to your web
> server)?
>
> Since you don't know what they are, you don't need them.


I think he's talking about the Certificate Revocation List that
Microsoft updated earlier this week.

http://technet.microsoft.com/en-us/s...visory/2641690

--
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
CFP with extended deadline of Mar. 31, 2011: The 2011 InternationalConference on Security and Management (SAM'11), USA, July 18-21, 2011 A. M. G. Solo comp.security.misc 0 03-18-2011 07:02 AM
13th European Symposium on Research in Computer Security (ESORICS'08) Alcaraz Tello comp.security.misc 0 01-18-2008 03:55 PM
Security '07 Call For Papers Lionel Garth Jones comp.security.misc 0 01-25-2007 04:32 PM
Call for Papers for the 16th USENIX Security Symposium Lionel Garth Jones comp.security.misc 0 10-02-2006 09:01 PM
SSRT5954 rev.4 - HP-UX TCP/IP Remote Denial of Service (DoS) Security Alert comp.security.misc 0 07-12-2005 11:27 AM


All times are GMT. The time now is 02:46 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45