Select the product you need help with
Update Available to Revoke Fraudulent Microsoft Certificates Issued by VeriSignArticle ID: 293811 - View products that this article applies to. This article was previously published under Q293811 On This PageSUMMARY
In March, 2001, VeriSign, Inc. announced that it had issued two digital certificates to an individual who fraudulently claimed to be a Microsoft employee. This issue is discussed at length in Microsoft Security Bulletin MS01-017
(http://www.microsoft.com/technet/security/bulletin/ms01-017.mspx)
. VeriSign has revoked these certificates, and they are listed in the current VeriSign Certificate Revocation List (CRL). However, because the VeriSign code-signing certificates do not specify a CRL Distribution Point (CDP), it is not possible for any browser's CRL-checking mechanism to locate and use the VeriSign CRL. Microsoft has developed an update that rectifies this problem. The update package includes a CRL that contains the two certificates, and an installable revocation handler that consults the CRL on the local computer, rather than attempting to use the CDP mechanism.
Important Notes
293818 For additional information about how to recognize these fraudulent certificates, click the article number below
to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/293818/EN-US/
)
Erroneous VeriSign-Issued Digital Certificates Pose Spoofing Hazard
293817 For additional information about how to revoke these certificates' trusted status, click the article number below
to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/293817/EN-US/
)
How to Recognize Erroneously-Issued VeriSign Code-Signing Certificates
293816 For additional information about how to remove VeriSign Commercial Software Publishers CA from the trusted store, click the article number below
to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/293816/EN-US/
)
How to Determine Whether You Have Accepted Trust for Fraudulent VeriSign-Issued Certificates
293819
(http://support.microsoft.com/kb/293819/EN-US/
)
How to Remove a Root Certificate from the Trusted Root Store
MORE INFORMATIONThe following file is available for download from the Microsoft Download Center: Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyId=43FD979A-03C1-4008-B38D-70E9BCD67454&displaylang=en)
119591
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
This update has been tested on the following operating systems with Internet Explorer 4.01 Service Pack 2, Internet Explorer 5.01 Service Pack 1 or Service Pack 2, and Internet Explorer 5.5 Service Pack 1:
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
To obtain the latest version of Internet Explorer, visit the following Microsoft Web site: http://www.microsoft.com/windows/ie
(http://www.microsoft.com/windows/ie)
PropertiesArticle ID: 293811 - Last Review: January 31, 2007 - Revision: 3.5 APPLIES TO
|



Back to the top








