Trustwave admits issuing man-in-the-middle digital certificate; Mozilla debates punishment
The issuing of subordinate root certificates to companies, so they can snoop on SSL-encrypted traffic, is a common industry practice
IDG News Service - Digital Certificate Authority (CA) Trustwave revealed that it has issued a digital certificate that enabled an unnamed private company to spy on SSL-protected connections within its corporate network, an action that prompted the Mozilla community to debate whether the CA's root certificate should be removed from Firefox.
The certificate issued by Trustwave is known as a subordinate root and enabled its owner to sign digital certificates for virtually any domain on the Internet. The certificate was to be used within a private network within a data loss prevention system, Trustwave said in a blog post on Saturday.
The CA took steps to ensure that the subordinate root could not be stolen or abused. The certificate was stored in a Hardware Security Module, a device built specifically for the management of digital keys, which ensured that its extraction was impossible, Trustwave said.
The company also performed on-site physical security audits to make sure that the system can't be removed from the premises and used to intercept SSL-encrypted (Secure Sockets Layer-encrypted) traffic on another network.
"We did not create a system where the customer could generate ad-hoc SSL certificates AND extract the private keys to be used outside this device," said Brian Trzupek, Trustwave's vice president for managed identity and authentication, in a discussion on Mozilla's bug tracker on Tuesday. "Nor could the subordinate root key ever get exported from the device."
Mozilla's community is currently debating whether the issuing of such certificates represents a breach of the software vendor's CA Certificate Policy, regardless of what security measures were put in place. CAs adhere to this Policy in order to have their root certificates trusted by Mozilla's products.
"We reserve the right to not include a particular CA certificate in our software products. This includes (but is not limited to) cases where we believe that including a CA certificate (or setting its "trust bits" in a particular way) would cause undue risks to users' security, for example, with CAs that knowingly issue certificates without the knowledge of the entities whose information is referenced in the certificates," Mozilla's CA Certificate Policy states.
Some users are asking Mozilla to remove Trustwave's root certificate from Firefox and Thunderbird because domain name owners were not aware that Trustwave was re-signing certificates in their name through a subordinate root.
"We're still evaluating the reports from Trustwave, and have not yet decided on a course of action. In the interim, we are pleased to hear that this subordinate certificate is being revoked. We encourage any other CAs with similar certificates to follow Trustwave's example of disclosure and revocation,"said Johnathan Nightingale, senior director of Firefox Engineering at Mozilla Corp.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- IDC Report: The Future of eMail is Social This paper discusses the changing nature of collaboration and work fueled by the social Web by examining current email trends and the emergence...
- The Business of Social Business Social business represents a significant transformational opportunity for organizations. Read this whitepaper to learn more.
- Six Ways Your Small Business Can Save with Internet Phone Service Traditional phone systems present two main problems for businesses: limited features and high costs. As a result, small businesses are migrating to Internet...
Red Hat Enterprise Linux - The Original Cloud Operating System
Linux adoption is growing against a number of measures, such as the
number of supercomputers that run Linux and the size of the contributing...
- Supercharge Your Web and Mobile App Development with High-Productivity Hybrid Cloud Webinar: Hear from industry experts about the amazing power at the intersection of next-generation web and mobile application development and cloud platforms.
- Webinar: Building a Big Data solution that's production-ready Big data solutions are no longer just a nice-to-have. All Internet White Papers | Webcasts