Page 1 of 1

untrusted SSL certificate

Posted: 13 Dec 2015, 22:36
by aus9
Google, Inc have just announced they are dumping one particular SSL CA certificate.

http://www.itnews.com.au/news/google-du ... oid-412962
Symantec's Class 3 Public Primary Certificate Authority (CA) root certifcate is no longer trusted by Google in its Chrome web browser, Android mobile operating system and other products

snip and it relates to

VeriSign Class 3 Public Primary Certification Authority G1

Read more: http://www.itnews.com.au/news/google-du ... z3uF6HFoIL
small boast follows....for those who adopted my certs script in the Nemesis forum, you don't have it. Not sure about the rest
But even if I did have it, my way allows you to configure out one specific (or more) certs which is not possible with Nemesis certs.

YMMV

Re: untrusted SSL certificate

Posted: 15 Dec 2015, 22:13
by brokenman
You've really got your finger on the pulse aus9!

Re: untrusted SSL certificate

Posted: 17 Dec 2015, 12:06
by aus9
small update

neither of those certs exist at
/etc/ca-certificates/extracted AFAIK so Nemesis users are safe, assuming they have done an update.