x****o 发帖数: 21566 | 1 呵呵
Chinese CA WoSign faces revocation after possibly issuing fake certificates
of Github, Microsoft and Alibaba
One of the largest Chinese root certificate authority WoSign issued many
fake certificates due to an vulnerability. WoSign's free certificate
service allowed its users to get a certificate for the base domain if they
were able to prove control of a subdomain. This means that if you can
control a subdomain of a major website, say percy.github.io, you're able to
obtain a certificate by WoSign for github.io, taking control over the entire
domain.
WoSign数字证书产品特别针对中国市场的特点和需求而设计,满足了各种用户需求、质
优价廉、全球通用、支持所有浏览器和服务器。由于性能价格比高、全面支持中文以及
本地化的优质服务,受到了广大高中低端用户的普遍欢迎,产品已经广泛应用于银行、
证券、基金、中国移动、中国电信和各大知名电子商务网站,其中,WoSign 微软代码
签名证书在中国市场占有率已经超过90%, SSL 证书中国市场占有率已经超过50% 。
WoSign 已经成为中国唯一拥有自己的根证书、自己品牌的、支持所有浏览器的、全系
列数字证书产品供应商,也是中国最大的、市场份额占绝对优势的数字证书产品供应商
http://www.percya.com/2016/08/chinese-ca-wosign-faces-revocation.html |
|