The Register: SSL Defeated in IE and Konqueror | Linux Today

The Register: SSL Defeated in IE and Konqueror

Written By
Web Webster
Web Webster
Aug 12, 2002

“A colossal stuff-up in Microsoft’s and KDE’s implementation of
SSL (Secure Sockets Layer) certificate handling makes it possible
for anyone with a valid VeriSign SSL site certificate to forge any
other VeriSign SSL site certificate, and abuse hapless Konqueror
and Internet Explorer users with impunity.

“In more detail, we have a certificate chain issue discovered by
Mike Benham of thoughtcrime.org. A chain is formed when an
intermediate certificate is trusted between server and client.
Supposedly, the intermediate is accepted only if it’s signed by the
certificate authority as safe for the purpose. If it’s merely
signed by another certificate’s key, it ought not to be trusted, or
at least the user should be warned. Unfortunately, due to a
preposterous security engineering oversight, IE and Konqueror don’t
bother to check this, so if a tricky site owner signs an
intermediate cert with another valid cert, users will be none the
wiser.

“The browser, Benham says, ‘should verify that the CN [Common
Name] field of the leaf certificate matches the domain it just
connected to, that it’s signed by the intermediate CA [Certificate
Authority], and that the intermediate CA is signed by a known CA
certificate. Finally, the Web browser should check that all
intermediate certificates have valid CA basic constraints…'”

Complete
Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.