Apple finally blocks untrusted DigiNotar SSL certificates in Mac OS X

Summary: Time to patch your Mac OS X to protect yourself against fraudulent DigiNotar SSL certificates

It's taken Apple two weeks, but finally the company has issued a patch for Mac OS X to block DigiNotar from the list of trusted root certificates and from the list of Extended Validation (EV) certificate authorities.

DigiNotar is one out of  hundreds of firms that are authorized to issue digital certificates used to verify the identity of a website. On August 30 the company announced that its servers had been compromised and that fake certificates might have leaked into the wild.

Here are the updates:

Additional information here:

Certificate Trust Policy

Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7.1, Lion Server v10.7.1

Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information

Description: Fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. This issue is addressed by removing DigiNotar from the list of trusted root certificates, from the list of Extended Validation (EV) certificate authorities, and by configuring default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not trusted.

Apple has yet to offer a patch to protect iOS users from fraudulent DigiNotar certificates.

Time to run Software Updates on your Macs!

Topic: Apple

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

4 comments
Log in or register to join the discussion
  • Can I ask why you didn't use the following title?

    Can I ask why you didn't use the following title?
    "Is OS X vulnerable to attack by stolen digital certificates?"

    And then spend the article explaining how yes, OS X is vulnerable to attack?

    Or was it your intention to make it sound like only Windows is vulnerable to attack?
    toddybottom
    • Not sure...

      @toddybottom

      Technically, Both OS X and Windows is vulnerable, if they're unpatched...

      Maybe he was just pointing out that it took Apple longer to patch than it did Microsoft:

      http://www.computerworld.com/s/article/9219746/Microsoft_flips_kill_switch_on_all_DigiNotar_certificates
      UrNotPayingAttention
    • RE: Apple finally blocks untrusted DigiNotar SSL certificates in Mac OS X

      @toddybottom

      It would be a tour-de-force for Adrian. All he has to do is find/replace Microsoft product terms with Apple product terms.

      C'mon Adrian! Don't tell me you forgot about the "article" you wrote on Windows? Or are you busy copy/pasting best kit for October already?
      mep01378
  • RE: Apple finally blocks untrusted DigiNotar SSL certificates in Mac OS X

    Something must have happened for them to finally take action.
    The one and only, Cylon Centurion