Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: Microsoft Certificate Updater SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Microsoft Certificate Updater

Microsoft released an automatic updated for untrusted certificates. A bid sad that we need this, but it does appear to be necessary to have a method to continuously update a bad certificate lists. The goal of the new updater is to allow for updates to the untrusted certificate store in one day or less after a new bad certificate is known.

Key revocation lists and OCSP were designed to notify clients of revoked certificates. However, these protocols haven't shown the scalability necessary to reliably notify clients of invalid certificates.

(thx Alex for pointing this out)

[1] http://blogs.technet.com/b/pki/archive/2012/06/12/announcing-the-automated-updater-of-untrustworthy-certificates-and-keys.aspx

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

I will be teaching next: Defending Web Applications Security Essentials - SANS San Francisco Spring 2020

Johannes

3698 Posts
ISC Handler
If these certificate updates keep requiring reboots it's going to greatly slow down their install rate :(
Anonymous
Happy to see a tool like this get released. I would think it wouldn't cause a reboot... anyone know if the KBs for previous cert updates caused a reboot?
mbrownnyc

19 Posts
#pedant mode on
"A bid sad" should be "A bit sad"
#pedant mode off
But yes, a loss of trust is always sad.
Anonymous
@mbrownnyc
KB2718704 didn't require a reboot.
David

11 Posts
KB2718704 didn't require a reboot on Vista & Win7 but did on XP
Greg

25 Posts
Soon enough, a security hole in this updater will require a Certificate Updater Updater. I hate to tell you this, but it's updaters all the way down.
Greg
1 Posts
Does this flaw have anything to do with this news article:

http://www.washingtonpost.com/world/national-security/us-israel-developed-computer-virus-to-slow-iranian-nuclear-efforts-officials-say/2012/06/19/gJQA6xBPoV_print.html
Gilbert

21 Posts

Sign Up for Free or Log In to start participating in the conversation!