Statement in Regard to DigiCert Revocation and Symantec Distrust
trustico.com
trustico.com
Uhm.. what??
Leaving aside the "it's okay we compromised the PRIVATE key because.." bit of this, is there something I'm missing here? You can extract the public key and fingerprint from a private key, so ... it's trivial to match based on that, right? Is there any merit to this statement whatsoever?
$ openssl x509 -pubkey -noout -in cert.pem | openssl rsa -pubin -outform der | openssl sha1
writing RSA key
(stdin)= 92635f3403046f4d7d0e0b40829dc24b0370478d
$ openssl rsa -in key.pem -pubout -outform der | openssl sha1
writing RSA key
(stdin)= 92635f3403046f4d7d0e0b40829dc24b0370478d