<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sysadmin Notes</title>
	<atom:link href="http://blogs.oregonstate.edu/sysadmin/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.oregonstate.edu/sysadmin</link>
	<description></description>
	<lastBuildDate>Tue, 16 Aug 2011 18:07:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Chrome errors with Tomcat</title>
		<link>http://blogs.oregonstate.edu/sysadmin/2011/08/16/chrome-errors-with-tomcat/</link>
		<comments>http://blogs.oregonstate.edu/sysadmin/2011/08/16/chrome-errors-with-tomcat/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 18:06:52 +0000</pubDate>
		<dc:creator>morgan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.oregonstate.edu/sysadmin/?p=12</guid>
		<description><![CDATA[I stumbled across an interesting problem&#8230; If you run a Tomcat SSL web server and have Chrome browsers as clients, you may see errors in Chrome. These errors are not the fault of Tomcat, but they are a bug in older versions of the Java JDK which Tomcat uses for SSL. Costin Manolache&#8217;s blog post [...]]]></description>
				<content:encoded><![CDATA[<p>I stumbled across an interesting problem&#8230;  If you run a Tomcat SSL web server and have Chrome browsers as clients, you may see errors in Chrome.  These errors are not the fault of Tomcat, but they are a bug in older versions of the Java JDK which Tomcat uses for SSL.  <a href="http://blog.webinf.info/2009/12/chrome-ssl-and-tomcat-or-other-jsse.html">Costin Manolache&#8217;s blog post</a> explains it fairly well.  The bug in JSSE was fixed in JDK 6u12.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.oregonstate.edu/sysadmin/2011/08/16/chrome-errors-with-tomcat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dueling Thawte Premium Server CA certificates</title>
		<link>http://blogs.oregonstate.edu/sysadmin/2011/07/19/dueling-thawte-premium-server-ca-certificates/</link>
		<comments>http://blogs.oregonstate.edu/sysadmin/2011/07/19/dueling-thawte-premium-server-ca-certificates/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 17:31:17 +0000</pubDate>
		<dc:creator>morgan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.oregonstate.edu/sysadmin/?p=5</guid>
		<description><![CDATA[Why are there two different Thawte Premium Server CA certificates out there? Thawte distributes one at their root certificates web site: Serial Number: 36 12 22 96 c5 e3 38 a5 20 a1 d2 5f 4c d7 09 54 Valid From: Wednesday, July 31, 1996 Valid to: Friday, January 01, 2021 Certificate SHA1 Fingerprint: e0 [...]]]></description>
				<content:encoded><![CDATA[<p>Why are there two different Thawte Premium Server CA certificates out there?<br />
Thawte distributes one at their <a href="https://www.thawte.com/roots/">root certificates</a> web site:</p>
<pre>Serial Number: 36 12 22 96 c5 e3 38 a5 20 a1 d2 5f 4c d7 09 54
Valid From: Wednesday, July 31, 1996
Valid to:  Friday, January 01, 2021
Certificate SHA1 Fingerprint: e0 ab 05 94 20 72 54 93 05 60 62 02 36 70 f7 cd 2e fc 66 66
Key Size: RSA(1024 Bits)</pre>
<p>but there is a different version distributed with Redhat, Debian, Firefox, and OS X:</p>
<pre>Serial Number: 1 (0x1)
Validity
     Not Before: Aug  1 00:00:00 1996 GMT
     Not After : Dec 31 23:59:59 2020 GMT
SHA1 Fingerprint=62:7F:8D:78:27:65:63:99:D2:7D:7F:90:44:C9:FE:B3:F3:3E:FA:9A</pre>
<p>If I build a certificate chain for an SSL web server using the one from Thawte&#8217;s web site, OS X says the site uses an invalid certificate.</p>
<p><b>*** Update ***</b></p>
<p>There ARE 2 different Thawte Premium Server CA certificates:</p>
<p><a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;id=AR1530&amp;actp=search&amp;viewlocale=en_US">MD5-signed</a><br />
<a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;id=AR1470&amp;actp=search&amp;viewlocale=en_US">SHA1-signed</a></p>
<p>We&#8217;ll see if they tell me why they did that&#8230;</p>
<p><b>*** Update 2 ***</b></p>
<p>Thawte was required by the browser vendors to sign their CA certs with SHA1 instead of MD5.  See here: <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;actp=CROSSLINK&amp;id=AD221">https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;actp=CROSSLINK&amp;id=AD221</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.oregonstate.edu/sysadmin/2011/07/19/dueling-thawte-premium-server-ca-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
