Does RCM have any vulnerabilites by using MD5 for referencing objects in the administration console?
Originally Published: 2009-01-14
Last Modified: 2023-10-06
Article Number
Applies To
RSA Certificate Manager (RCM)
Message-Digest Algorithm (MD5)
Issue
All certificates used in RCM use the MD5 number for reference
Web sites regarding MD5 vulnerability:
http://www.win.tue.nl/hashclash/rogue-ca/
http://www.rsa.com/blog/blog_entry.aspx?id=1411
http://broadcast.oreilly.com/2008/12/the-sky-is-not-falling-on-toda.html
Resolution
Since RCM only uses the MD5 hash as a reference number for the nameing of object in the database, there is no trust chain to exploit as shown with the recent MD5 vunerability.
For information on the MD5 vunerability with Root CAs, see solution What algorithm does RCM used to sign the certificates? .
Related Articles
Access Manager - Multiple vulnerabilities reported in Spring Source "spring-core-3.0.3.RELEASE.jar" - False Positives 57Number of Views How to view a certificate fingerprint as SHA-256, SHA-1 or MD5 using OpenSSL for RSA Authentication Manager 81Number of Views CERT/CC Vulnerability Note VU#475445: Potential Impact on RSA Products 32Number of Views Scan of RSA Certificate Manager 6.7 show vulnerabilities with Apache 1.3.33 49Number of Views Error 'Invalid X.509 certificate uploaded' when adding a new application 59Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog RSA Authentication Manager 8.9 Patches and Hotfixes Readme
Don't see what you're looking for?