LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-13-2009, 05:33 PM   #1
linuxrocks123
LQ Newbie
 
Registered: Aug 2006
Posts: 5

Rep: Reputation: 0
Konqueror SSL Problem


Hi,

I've been having an issue with using Konqueror on the Zions Bank website, https://www.zionsbank.com. It claims that the certificate is signed by an unknown authority. This is the case with both Konqueror for KDE 3.5 on Gentoo and with Konqueror for KDE 4 on Slackware. Every other browser I have used reports no problem with the site's authentication, but NetCraft indicates that there is a self-signed certificate in the authenticity chain: http://toolbar.netcraft.com/site_rep....zionsbank.com.

Could anyone explain to me what's going on here?

Thanks in advance,
---linuxrocks123
 
Old 08-15-2009, 02:19 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
These are listed in a Sun document as in their default trust list.
Entrust.net Premium 2048 Secure Server CA
Entrust.net Secure Personal CA
Entrust.net Secure Server CA

http://docs.sun.com/source/816-6732-10/authctn.html
So they are legit it seems.
It is up to the web browser publisher to decide which root authorities to trust. Many feel that the number of CA's has gotten out of control, such as Steve Gibson's joke about the Hong Kong post office. The root authority and the certificate authority are one in the same. I guess it begs the question, does one link make up a chain (of authority).

Anyway, it isn't the bank's certificate that isn't being trusted, it's the CA's because it is self signed. If you personally know that this is a real bank, then you probably can trust it.

That might be a good policy by Konqueror. Imagine an attacker importing certificates for their own fake CA & root server on your browser and issuing them to his own phishing sites. Maybe a stretch, but I'm sure there may be more than a handful of computer techs who might do that for cash. Hopefully such a tech won't know that konqueror will trip it up, or the attacker could just add another CA in the chain.

Last edited by jschiwal; 08-15-2009 at 02:38 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
vsftpd SSL problem (522 SSL connection failed) stringZ Linux - Server 8 05-05-2009 02:27 PM
konqueror and ssl bong.mau Linux - Security 3 04-24-2007 10:18 AM
SSL Connections / second and SSL Accelerator Cards on Linux LinuxGeek Linux - Networking 0 06-10-2006 08:18 AM
need help with apach virtual hosts ssl/non ssl sites danthach Linux - Networking 3 05-25-2006 06:40 AM
sftp doesn't work in Konqueror after SSH/SSL upgrade Supernaut Slackware 4 10-28-2003 02:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration