Revoking Trust in DigiCert Sdn. Bhd Intermediate Certificate Authority
Issue
Entrust, Inc., a certificate authority in Mozilla’s root program, has informed us that one of their subordinate CAs, the Malaysian company DigiCert Sdn. Bhd, has issued 22 certificates with weak keys. While there is no indication they were issued fraudulently, the weak keys have allowed the certificates to be compromised. Furthermore, certificates from this CA contain several technical issues. They lack an EKU extension specifying their intended usage and they have been issued without revocation information.
Read moreAttack against TLS-protected communications
UPDATE 10.18.11: Today, Oracle is releasing a patch update to Java SE to address this vulnerability. We recommend that users update their Java plugin to ensure that they have the latest and most secure fixes. Windows users on auto update should start seeing the updates as early as this week. Users can also manually download the update here: http://java.com. Apple distributes Java updates directly for OS X. We will not be Read more