Friday, September 9, 2011

DigiNotar Debacle: Apple Certificate Trust Policy Update

Security Update 2011-005
Certificate Trust Policy

Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7.1, Lion Server v10.7.1

Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information

Description: Fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. This issue is addressed by removing DigiNotar from the list of trusted root certificates, from the list of Extended Validation (EV) certificate authorities, and by configuring default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not trusted.


After remaining silence for more than a week, Apple has finally released an update for OSX to deal with the DigiNotar hack fallout. Now what about iOS??

No comments:

Post a Comment