CERT-In Advisory
CIAD-2012-0050
Microsoft Alert for Minimum Certificate Key Length
Original Issue Date: October 19, 2012
Severity Rating: High
Systems Affected
- Windows XP SP3
- Windows XP Professional x64 Edition SP2
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista SP2
- Windows Vista x64 Edition SP2
- Windows Server 2008 for 32-bit Systems SP2
- Windows Server 2008 for x64-based Systems SP2
- Windows Server 2008 for Itanium-based Systems SP2
- Windows 7 for 32-bit Systems SP1 and prior
- Windows 7 for x64-based Systems SP1 and prior
- Windows Server 2008 R2 for x64-based Systems SP1 and prior
- Windows Server 2008 R2 for Itanium-based Systems SP1 and prior
- Windows Server 2008 for 32-bit Systems SP2 (Server Core installation)
- Windows Server 2008 for x64-based Systems SP2 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems SP1 and prior (Server Core installation)
Overview
Microsoft has released a security advisory regarding restricting the use of RSA certificates that have key size less than 1024 bits in Windows OS to reduce the risk of unauthorized exposure of sensitive information.
Description
The private keys used in RSA certificates that are less than 1024 bits in length are prone to cryptanalysis. This could allow an attacker to gain access to the private key to duplicate the certificates and use them fraudulently to spoof content, perform phishing attacks, or perform man-in-the-middle attacks.
As per Microsoft: ¿This update impacts applications and services that use RSA keys for cryptography and call into the CertGetCertificateChain function. These applications and services will no longer trust certificates with RSA keys less than 1024 bits in length. Examples of impacted applications and services include but are not limited to encrypted email, SSL/TLS encryption channels, signed applications, and private PKI environments. Certificates that use cryptographic algorithms other than RSA are not affected by this update.¿
Solution
Apply appropriate fixed versions as mentioned in Microsoft Security Advisory
http://technet.microsoft.com/en-us/security/advisory/2661254
Note: - System administrators are advised to test this update in a non-production environment before applying to the entire production servers.
Vendor Information
Microsoft
http://support.microsoft.com/kb/2661254
http://technet.microsoft.com/en-us/security/advisory/2661254
References
Microsoft
http://support.microsoft.com/kb/2661254
http://technet.microsoft.com/en-us/security/advisory/2661254
http://blogs.technet.com/b/msrc/archive/2012/09/06/september-ans-and-an-important-heads-up-concerning-certificates.aspx
US-CERT
http://www.us-cert.gov/cas/techalerts/TA12-251A.html
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|