
CVE-2011-0228 구형 아이디바이스/펌웨어용 수정
v1.2 : DigiNotar 블랙리스트
v1.1 : 반복된 리프 false positives 버그 수정
v1.0 : 초기 릴리즈
https://github.com/jan0/isslfix/downloads
83aa7a01f4377d3e5ec2e1af9c99602a isslfix_1.2.deb 1.2 cydia 패키지
daa5c6efae5b36690153e715712e265e isslfix_1.1.deb 1.1 cydia 패키지 (fix1과 동일)
51560b2e1cc888f708c8c84c62be75a5 isslfix-fix1.deb 반복된 리프 false positives 수정을 위한 테스트 패키지
eee21f50d677a1edd6b8700f045e60f7 isslfix_1.0.deb 실제 cydia의 1.0 cydia 패키지
df580a7179b24ca1dfdd637cbcdf8062 isslfix.deb cydia에 제출된 버전 1.0
f22887c41bc9c663f6a181c2e8e9fd03 isslfix-test3.deb 테스트 버전, Comodo 블랙리스트 제외
경고 : 문제 발생 시를 대비하여 설치 전에 기기를 백업하십시오...
dpkg -i isslfix.deb
launchctl unload /System/Library/LaunchDaemons/com.apple.securityd.plist
launchctl load /System/Library/LaunchDaemons/com.apple.securityd.plist
https://issl.recurity.com을 방문하여 작동 여부를 확인하세요.
이미 수정 사항을 적용하지 않고 이 페이지를 방문했다면, 페이지를 새로고침하거나 Safari의 캐시를 지우십시오.
syslog에 "Cannot Verify Server Identity" 팝업과 다음 메시지가 표시되어야 합니다:
<Warning>: iSSLFix: Certificate <1BDC0A9E-7FC6-4BA4-A9E5-41F206B82D81> in chain starting at <issl.recurity.com> has isCA=0 => possible MITM attempt, making validation fail
securityd가 다시 시작되면 기존 프로세스와 데몬은 securityd와의 '연결'을 잃게 되며, Security 프레임워크(키체인, 인증서 검증 등)에 대한 대부분의 호출이 실패합니다: iTunes가 기기에 연결할 수 없고, 앱이 키체인에 접근할 수 없는 등의 문제가 발생합니다. 이러한 문제는 기기를 재부팅하면 사라집니다.
securityd가 충돌한 경우 (/Library/Logs/CrashReporter/ 확인), 재부팅 전에 패키지를 제거하십시오 (dpkg -r isslfix).
구형 펌웨어 기기의 경우 iOS 4.3.2에 추가된 블랙리스트가 복제됩니다 (blacklist.c 및 comodo.h 참조).
다음 인증서의 공개 키는 v1.2에서 블랙리스트에 등록되었습니다.
DigiNotar Root CA (88 68 bf e0 8e 35 c4 3b 38 6b 62 f7 28 3b 84 81 c8 0c d7 4d)
DigiNotar Cyber CA (ab f9 68 df cf 4a 37 d7 7b 45 8c 5f 72 de 40 44 c3 65 bb c2)
DigiNotar Services 1024 CA (fe dc 94 49 0c 6f ef 5c 7f c6 f1 12 99 4f 16 49 ad fb 82 65)
DigiNotar PKIoverheid CA Organisatie - G2 (bc 5d 94 3b d9 ab 7b 03 25 73 61 c2 db 2d ee fc ab 8f 65 a1)
DigiNotar Root CA G2 (29 0d db 3f 07 52 e5 0b d4 21 68 2e 24 4a de 5b 5a 96 f2 21)
http://support.apple.com/kb/HT4824
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0228
https://github.com/hubert3/iSniff
http://support.apple.com/kb/HT4606
http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html
https://bugzilla.mozilla.org/show_bug.cgi?id=643056
http://hg.mozilla.org/mozilla-central/rev/f6215eef2276
http://codereview.chromium.org/7791032/
https://bugzilla.mozilla.org/show_bug.cgi?id=682927
http://blog.mozilla.com/security/2011/09/02/diginotar-removal-follow-up/