http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2022/untrusted-harica-onion-certificates
But if I download HARICA’s 2021 Root CA, it has the following properties: Identity: HARICA TLS ECC Root CA 2021 Public key: MHYwEAYHKoZI...kEFYkBVyp6G3 Signature: Root CAs are self-signed . So something cool can be done here - since HARICA possesses the keypair for both their 2015 and 2021 Root CAs, they can arbitrarily create new certificates that include either root CA’s public key, and then can be signed by either root CA’s public key!
1 similar result skipped