You are on page 1of 3

MD5

http://www.win.tue.nl/hashclash/rogue-ca/

hash-
,MD5
( MD5)
MD5 2004

CA , "
Root CA
DNS

CA- ,MD5-
Root CAs
MD5-


Real certificate

Rogue CA certificate

Serial number
Validity period

Rogue CA Cert
Chosen prefix
(difference)

Real cert domain name

Rogue CA RSA key


Rogue CA x.509 extensions
(with CA bit!)

Real cert RSA key


X.509 extensions
signature

Collision bits
(computed)
Identical bytes (copied
from real cert)

Netscape comment
extension (contents
ignored by browsers)
signature

,CA- , ,
.validity period- serial number

You might also like