File weak-ssl-certificates.diff of Package libqt4.1378

commit e1d6df4e5931ee49b4b68dd5a33146f5639268b7
Author: Peter Hartmann <peter.hartmann@nokia.com>
Date:   Fri Nov 4 16:56:12 2011 +0100

    SSL: blacklist intermediate certificates that issued weak certs
    
    ... as did browser vendors.
    Tested manually with affected CA certificates.
    
    Reviewed-by: Richard J. Moore <rich@kde.org>

diff --git a/src/network/ssl/qsslcertificate.cpp b/src/network/ssl/qsslcertificate.cpp
index 2a2ad55..85cd06c 100644
--- a/src/network/ssl/qsslcertificate.cpp
+++ b/src/network/ssl/qsslcertificate.cpp
@@ -814,6 +814,9 @@ static const char *certificate_blacklist[] = {
 //    "(has not been seen in the wild so far)", "Stichting TTP Infos CA," // compromised during DigiNotar breach
     "1184640175", "DigiNotar Root CA", // DigiNotar intermediate cross-signed by Entrust
     "1184644297", "DigiNotar Root CA", // DigiNotar intermediate cross-signed by Entrust
+
+    "120001705", "Digisign Server ID (Enrich)", // (Malaysian) Digicert Sdn. Bhd. cross-signed by Verizon CyberTrust
+    "1276011370", "Digisign Server ID - (Enrich)", // (Malaysian) Digicert Sdn. Bhd. cross-signed by Entrust
     0
 };
 
openSUSE Build Service is sponsored by