Class3 Subroot Re-sign - Press Release (English)

CAcert-Press Release

June 04, 2011

New signatures for CAcert-Class 3-Subroot-certificate - Changes for users of CAcert-Certificates

CAcert is going to re-sign its Class 3-certificate on June xxth with a new SHA256-based signature. The MD5-based signature on the old certificate is seen as not secure any more by Mozilla and is therefore deprecated. Mozilla is going to drop support for MD5-signed Class 3-subroot and end-entity certificates after 30th June. Users of Mozilla products such as Firefox and Thunderbird may experience errors when these programs try to verify such certificates.

In order to avoid warnings, webmasters and users of CAcert's Class 3-certificates will have to download and install the newly-signed certificates from CAcert's website www.cacert.org. The same procedure applies if the Class 3-certificate is used for secure e-mail communication, for code signing, or document signing.

The procedure in short:

  1. Download the new Class 3 PKI Key from http://www.cacert.org/index.php?id=3

  2. Either install it directly in your browser, or any other client program you use the certificate for, or save it to the SSL configuration directory of your webserver. For Apache this may be: /etc/apache2/ssl/class3.crt (PEM-Format)
  3. Verify the SHA1-fingerprint of the downloaded certificate:
    • AD:7C:3F:64:FC:44:39:FE:F4:E9:0B:E8:F4:7C:6C:FA:8A:AD:FD:CE

    • Example Commandline:
      • openssl x509 -fingerprint -noout -in class3.crt
    • Or look at the fingerprint when importing the certificate into the webbrowser
  4. Webmaster now re-create the necessary hash with c_rehash, or the like

By using the safe SHA256-hash CAcert is focussing on securing the internet on a continuing basis. Further information is given on CAcert's Wiki page https://wiki.cacert.org/FAQ/Class3Resign.

