Re: [saag] [Cfrg] Further MD5 breaks: Creating a rogue CAcertificate

"Timothy J. Miller" <tmiller@mitre.org> Wed, 07 January 2009 06:35 UTC

Return-Path: <saag-bounces@ietf.org>
X-Original-To: saag-archive@ietf.org
Delivered-To: ietfarch-saag-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 16F1728C147; Tue, 6 Jan 2009 22:35:17 -0800 (PST)
X-Original-To: saag@core3.amsl.com
Delivered-To: saag@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 54B1F3A6987 for <saag@core3.amsl.com>; Tue, 6 Jan 2009 06:08:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.579
X-Spam-Level:
X-Spam-Status: No, score=-6.579 tagged_above=-999 required=5 tests=[AWL=0.020, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4Wux438AGMVL for <saag@core3.amsl.com>; Tue, 6 Jan 2009 06:08:57 -0800 (PST)
Received: from smtp-bedford.mitre.org (smtp-bedford.mitre.org [129.83.20.191]) by core3.amsl.com (Postfix) with ESMTP id 74AAE3A68F2 for <saag@ietf.org>; Tue, 6 Jan 2009 06:08:55 -0800 (PST)
Received: from smtp-bedford.mitre.org (localhost.localdomain [127.0.0.1]) by smtp-bedford.mitre.org (8.13.1/8.13.1) with ESMTP id n06E8eNv012872 for <saag@ietf.org>; Tue, 6 Jan 2009 09:08:42 -0500
Received: from imchub2.MITRE.ORG (imchub2.mitre.org [129.83.29.74]) by smtp-bedford.mitre.org (8.13.1/8.13.1) with ESMTP id n06E8dZg012792; Tue, 6 Jan 2009 09:08:39 -0500
Received: from [129.83.200.4] (129.83.200.4) by imchub2.MITRE.ORG (129.83.29.74) with Microsoft SMTP Server (TLS) id 8.1.311.2; Tue, 6 Jan 2009 09:08:39 -0500
Message-ID: <496365C7.4040804@mitre.org>
Date: Tue, 06 Jan 2009 08:08:07 -0600
From: "Timothy J. Miller" <tmiller@mitre.org>
User-Agent: Thunderbird 2.0.0.19 (Windows/20081209)
MIME-Version: 1.0
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
References: <E1LK7XY-0004kA-BQ@wintermute01.cs.auckland.ac.nz>
In-Reply-To: <E1LK7XY-0004kA-BQ@wintermute01.cs.auckland.ac.nz>
X-Mailman-Approved-At: Tue, 06 Jan 2009 22:35:14 -0800
Cc: "cfrg@irtf.org" <cfrg@irtf.org>, "ietf-smime@imc.org" <ietf-smime@imc.org>, "saag@ietf.org" <saag@ietf.org>, "ietf-pkix@imc.org" <ietf-pkix@imc.org>, "pmhesse@geminisecurity.com" <pmhesse@geminisecurity.com>, "mike-list@pobox.com" <mike-list@pobox.com>
Subject: Re: [saag] [Cfrg] Further MD5 breaks: Creating a rogue CAcertificate
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/saag>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============0197123008=="
Sender: saag-bounces@ietf.org
Errors-To: saag-bounces@ietf.org

Peter Gutmann wrote:
> "Timothy J. Miller" <tmiller@mitre.org> writes:
> 
>> The only reliable way to nuke a trusted cert from Windows is touch management
>> of workstations.
> 
> It's worse than that, there is no reliable way to remove trusted certs from
> Windows.  See Paul Hoffman's analysis at
> http://www.proper.com/root-cert-problem/.

I've corresponded with Paul about that in the past.  Root 
auto-installation can be disabled, users can be blocked from installing 
roots in both the machine and user store (requires domain GPO, IIRC), 
and subjectInfoAccess chasing can be disabled (Vista "feature").

Incomplete answer for general users, yes, but it's there nonetheless. 
Presumably if you're touch managing workstations for trust anchor 
removal you can verify that these settings are all in place.  :)

The roots that shouldn't be removed are the ones needed to boot (i.e., 
validate authenticode signatures).  That's more than a few in XP.

-- Tim

_______________________________________________
saag mailing list
saag@ietf.org
https://www.ietf.org/mailman/listinfo/saag