Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Client script access to server cert info

From: Maupin, Tony <Tony.Maupin(at)integris-health.com>
Date: Mon Apr 14 2003 - 09:55:05 EDT


What you're looking for is called a "certificate parsing module". Do a search on that term and/or add open source to the search depending on what you're looking for. It will do everything you are asking and more.

Tony Maupin

-----Original Message-----
From: Brass, Phil (ISS Atlanta) [mailto:PBrass@iss.net] Sent: Sunday, April 13, 2003 11:21 PM
To: webappsec@securityfocus.com
Subject: RE: Client script access to server cert info

To clarify, what I'm looking for is a way for script on a page to access the server certificate information used during the SSL connection over which the page was provided. I.e. if Alice requests a page from bob.com, but the bob.com server returns a certificate that actually says mallory.com, and Alice presses "OK" when prompted about the discrepancy, it would be nice if there was a way to detect this using script that ran in the browser. I'm trying to find out if anybody knows of any browser/DOM/DHTML objects that contain a description (signing chain, CN, fingerprint, whatever) of the actual server certificate information presented during the SSL handshake.

Phil

> -----Original Message-----
> From: Brass, Phil (ISS Atlanta)
Received on Mon Apr 14 12:18:07 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library