SSL Certificate Chain Contains Illegitimate TURKTRUST Intermediate CA

medium Nessus Plugin ID 63398


The SSL certificate chain for this service is not to be trusted.


The X.509 certificate chain sent by the remote host either contains or is signed by an intermediate Certificate Authority (CA) that was accidentally issued by TURKTRUST.

Certificate chains descending from this intermediate CA could allow an attacker to perform man-in-the-middle attacks and decode traffic.


Ensure that your software or operating system blacklists the intermediate CAs.

See Also

Plugin Details

Severity: Medium

ID: 63398

File Name: ssl_turktrust.nasl

Version: 1.5

Type: remote

Family: General

Published: 1/7/2013

Updated: 10/26/2020

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information


Risk Factor: Medium

Base Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Information

Required KB Items: Settings/ParanoidReport, SSL/Supported

Vulnerability Publication Date: 12/26/2012