TURKTRUST Incident Raises Renewed Questions About CA System
The series of missteps and failures that led to a Turkish government-related agency eventually ending up with a valid wild card certificate for Google domains began in June 2011 when the TURKTRUST certificate authority began preparing for an audit of its systems and started moving some certificate profiles from production systems to test systems. Two months later, a pair of subordinate certificates--which carried the full power and inherited trust of TURKTRUST's root certificate as far as most browsers were concerned--were issued, and one of them later was used by a Turkish government transportation and utility agency to create an attacker's holy grail: a valid certificate enabling him to intercept encrypted Google traffic.
read more
Source:
TURKTRUST Incident Raises Renewed Questions About CA System