How to make a Root CA 09-10-2011, 04:30 PM
#1
Hi, you've reached my humble article, I hope you all enjoy it and if you like it and would like to see more posts from me, please don't forget to hit the plus +Rep!
As you probably know (or did not know) Digital certificates are verified using a chain of trust. The trust anchor for the digital certificate is the Root Certificate Authority (CA).
In Firefox you can see your digital signing certificates by going to preferences then clicking the advanced tab follow by view certificates.
Many software applications including your web-browser assume these root certificates are trustworthy on the user's behalf.
For example, a Web browser uses them to verify identities within SSL/TLS secure connections.
However, this implies that the user trusts their browser's publisher, the certificate authorities it trusts, to faithfully verify the identity and intentions of all parties that own the certificates.
The most common commercial variety is based on the X.509 standard, which normally includes a digital signature from a certificate authority (CA).
With me so far? Ok, now lets say you would like to use a Certificate to protect visitors to your site, to do this people use Secure Sockets Layer (SSL) and a layer of encryption. You yourself can create whats known as a Self-Signed certificate which you can issue to your visitors when they arrive on pages secured with HTTPS.
However here comes the bummer part, because your SSL Certificate is Self-Signed people visiting your web-site using SSL will receive a warning about the connection being Untrusted & the browser will prompt them to add a security exception.
Are you getting a site certificate error when trying to access a protected web site?
Portions of that web site use SSL protection to help secure their content. Access to these areas require that a site security certificate is loaded into your browser to add a self-signed certificate to Firefox you would have to add an exception.
These areas can only be accessed directly with no warning if you have a DoD Public Key Infrastructure (PKI) or Common Access Cards (CAC) with a SIGNED Root Certificate from a SIGNING Authority! The Signing Authority in this case normally being Equifax, GeoTrust, etc.
These Signing Authorities are regulated and controlled by the Government, so that means that whilst you have great security using a self-signed certificate, but if you want people to stop getting a warning about your site being untrusted then you would have to PAY for a security certificate and then PAY for it to be Signed and re-issued by a SIGNING Authority.
That means that they the CA issuer or the Government then own the PKI & Decryption Sequence to your SSL connections. So Big Brother is literally watching.
These same signing authorities are used for everything, even the mighty and powerful Google has to get it's Certificates which use SSL for eMail from a Signing Authority owned and operated by a Governing Body.
So now we have to ask ourselves the question is SSL really that secure? Oh sure it stops an attacker from reading and intercepting our communications but not the people who PUBLISH the SSL Certificates, so now we have to ask ourselves do we trust these people not to read people's eMails? This would be the same Government that had listening stations in telephone exchanges in the past listening to peoples private and personal telephone conversations under the guise of it all being in the interests of National Security.
Do you trust them & it? A lot has been said in the past about Google being Big Brothers watchdog & many other social networking sites like Facebook (faceache) & Twitter.
There have been two major Certificate Authority (CA) attacks this year. In March, a hacker successfully penetrated one of the largest CA's on the Web--Comodo--and managed to issue bogus certificates to himself (including one for Yahoo). The second incident took place this week when a Dutch CA, Diginotar, was compromised and a number of fake certificates were issued.
So how does a Certificate Authority attack work? Certificate bandits break into companies--such as Comodo and Diginotar--that issue digital credentials that your browser uses to verify a websites identity and its this credential that tells your browser that the site can be "trusted," i.e. that it's not dangerous.
Certificate bandits, however, can undermine this entire process by issuing fake certificates to themselves that allow them to masquerade as "safe" sites, such as Google, Mozilla, Skype, and AOL.
Well I am not going to cover how you can do that! But what I will show you is how to do in this humble article, is how YOU the end user can create your very own Root CA and have it signed by yourself. Thats right, no more warnings or errors about the site connection being untrusted and whats more it'll use high grade military strength cryptography and because you are the SIGNING Authority only you have access to the Decryption of the PKI.
Your going to need to download an addons for your Firefox web-browser it's called Key Manager and you can get it here.
https://addons.mozilla.org/en-US/firefox...y-manager/
Once it's installed and you've restarted Firefox to enable it, you can move onto the next part which is the cool bit, hacking your very own Root CA.
Click on the new part in browser task bar called Key Manager and a new Window will open, next click on Generate Self-Signed Cert.
Now you can pretty much see the parts that need to be changed, goto the bit that says Sig Algorithm and change that to SHA-512 then change the Key Size to 2048 (high grade) RC4.
Now open the Advanced Tab. Goto std. Extensions (standard) and select the options you require for your certificate and make sure you click the part that says "is CA?" incremental length can be set to 00, then goto NS Extensions and set the parts you want, in this case I used SSL Server, SSL CA, unticked SSL Client S/MIME (mail) and Object signing. then hit Create Certificate.
Congrat's you now have a Root CA which has been Digitally verified and SIGNED.
If you explore the other options in that program you might even find a few options like sign Bogus GMAIL certificate etc.. But thats another thread!
:epic:
A lot of people will be going WTF? What would I do that for.
It's for Apache Admins to create SSL sockets using a Root Certificate for their website hosted locally on there webserver. (hope I didn't loose you in long winded explanation!)
As you probably know (or did not know) Digital certificates are verified using a chain of trust. The trust anchor for the digital certificate is the Root Certificate Authority (CA).
In Firefox you can see your digital signing certificates by going to preferences then clicking the advanced tab follow by view certificates.
Many software applications including your web-browser assume these root certificates are trustworthy on the user's behalf.
For example, a Web browser uses them to verify identities within SSL/TLS secure connections.
However, this implies that the user trusts their browser's publisher, the certificate authorities it trusts, to faithfully verify the identity and intentions of all parties that own the certificates.
The most common commercial variety is based on the X.509 standard, which normally includes a digital signature from a certificate authority (CA).
With me so far? Ok, now lets say you would like to use a Certificate to protect visitors to your site, to do this people use Secure Sockets Layer (SSL) and a layer of encryption. You yourself can create whats known as a Self-Signed certificate which you can issue to your visitors when they arrive on pages secured with HTTPS.
However here comes the bummer part, because your SSL Certificate is Self-Signed people visiting your web-site using SSL will receive a warning about the connection being Untrusted & the browser will prompt them to add a security exception.
Are you getting a site certificate error when trying to access a protected web site?
Portions of that web site use SSL protection to help secure their content. Access to these areas require that a site security certificate is loaded into your browser to add a self-signed certificate to Firefox you would have to add an exception.
These areas can only be accessed directly with no warning if you have a DoD Public Key Infrastructure (PKI) or Common Access Cards (CAC) with a SIGNED Root Certificate from a SIGNING Authority! The Signing Authority in this case normally being Equifax, GeoTrust, etc.
These Signing Authorities are regulated and controlled by the Government, so that means that whilst you have great security using a self-signed certificate, but if you want people to stop getting a warning about your site being untrusted then you would have to PAY for a security certificate and then PAY for it to be Signed and re-issued by a SIGNING Authority.
That means that they the CA issuer or the Government then own the PKI & Decryption Sequence to your SSL connections. So Big Brother is literally watching.
These same signing authorities are used for everything, even the mighty and powerful Google has to get it's Certificates which use SSL for eMail from a Signing Authority owned and operated by a Governing Body.
So now we have to ask ourselves the question is SSL really that secure? Oh sure it stops an attacker from reading and intercepting our communications but not the people who PUBLISH the SSL Certificates, so now we have to ask ourselves do we trust these people not to read people's eMails? This would be the same Government that had listening stations in telephone exchanges in the past listening to peoples private and personal telephone conversations under the guise of it all being in the interests of National Security.
Do you trust them & it? A lot has been said in the past about Google being Big Brothers watchdog & many other social networking sites like Facebook (faceache) & Twitter.
There have been two major Certificate Authority (CA) attacks this year. In March, a hacker successfully penetrated one of the largest CA's on the Web--Comodo--and managed to issue bogus certificates to himself (including one for Yahoo). The second incident took place this week when a Dutch CA, Diginotar, was compromised and a number of fake certificates were issued.
So how does a Certificate Authority attack work? Certificate bandits break into companies--such as Comodo and Diginotar--that issue digital credentials that your browser uses to verify a websites identity and its this credential that tells your browser that the site can be "trusted," i.e. that it's not dangerous.
Certificate bandits, however, can undermine this entire process by issuing fake certificates to themselves that allow them to masquerade as "safe" sites, such as Google, Mozilla, Skype, and AOL.
Well I am not going to cover how you can do that! But what I will show you is how to do in this humble article, is how YOU the end user can create your very own Root CA and have it signed by yourself. Thats right, no more warnings or errors about the site connection being untrusted and whats more it'll use high grade military strength cryptography and because you are the SIGNING Authority only you have access to the Decryption of the PKI.
Your going to need to download an addons for your Firefox web-browser it's called Key Manager and you can get it here.
https://addons.mozilla.org/en-US/firefox...y-manager/
Once it's installed and you've restarted Firefox to enable it, you can move onto the next part which is the cool bit, hacking your very own Root CA.
Click on the new part in browser task bar called Key Manager and a new Window will open, next click on Generate Self-Signed Cert.
Now you can pretty much see the parts that need to be changed, goto the bit that says Sig Algorithm and change that to SHA-512 then change the Key Size to 2048 (high grade) RC4.
Now open the Advanced Tab. Goto std. Extensions (standard) and select the options you require for your certificate and make sure you click the part that says "is CA?" incremental length can be set to 00, then goto NS Extensions and set the parts you want, in this case I used SSL Server, SSL CA, unticked SSL Client S/MIME (mail) and Object signing. then hit Create Certificate.
Congrat's you now have a Root CA which has been Digitally verified and SIGNED.
If you explore the other options in that program you might even find a few options like sign Bogus GMAIL certificate etc.. But thats another thread!
:epic:
A lot of people will be going WTF? What would I do that for.
It's for Apache Admins to create SSL sockets using a Root Certificate for their website hosted locally on there webserver. (hope I didn't loose you in long winded explanation!)
(This post was last modified: 09-10-2011, 06:08 PM by Hussain.)

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)

