Anonymous Monk has asked for the wisdom of the Perl Monks concerning the following question:

You may have seen this http://news.slashdot.org/story/11/03/23/1957200/Phony-Web-Certs-Issued-For-Google-Yahoo-Skype, phony ssl certificates got released, and subsequently revoked.

How does this affect LWP/Mozilla::CA?

Is there some kind of Revocation list? How would I specify that, or is there a module like Mozilla::CA (I didn't see one)?

It would be nice to let the OS manage this, like with Win32::Crypt::API or some such :)

  • Comment on LWP , Mozilla::CA, and Phony SSL Certificates

Replies are listed 'Best First'.
Re: LWP , Mozilla::CA, and Phony SSL Certificates
by afoken (Chancellor) on Mar 24, 2011 at 19:55 UTC
    Is there some kind of Revocation list? How would I specify that,

    Good question! It seems there is at least a script to update the git repository.

    It would be nice to let the OS manage this, like with Win32::Crypt::API or some such :)

    Feel free to write a wrapper module.

    Alexander

    --
    Today I will gladly share my knowledge and experience, for there are no sweeter words than "I told you so". ;-)