How to Distrust a CA
In a sub-continuation of Laura’s earlier article describing the now broken state of MD5 hashes, I’d like to provide a more concise one-stop-shop on how to distrust a CA in the event that this threat becomes more of an attacking reality.
Firefox / Thunderbird
- In the Menu Bar select “Tools”
- Select “Options”
- Select “Advanced” tab
- Click “View Certificates”
- Select the “Authorities” tab
- Select the CA that you would like to distrust “Equifax Secure Global eBusiness CA-1″ in this scenario.
- Select “Edit” button
- Uncheck all three areas of trust
- Select “OK” and exit out, or repeat for any other CAs you would like to distrust
Internet Explorer 7
- Select “Tools” in the Menu Bar*
- Select “Internet Options”
- Select the “Content” tab
- Select the “Certificates” button
- Select the “Trusted Root Certificate Authorities” tab
- Select the CA that you would like to distrust “Equifax Secure Global eBusiness CA-1″ in this scenario.
- Select the “Advanced” button
- Uncheck all trust options
- Select “OK” and exit out, or repeat for any other CAs you would like to distrust
*To make IE7’s Menu Bar visible you need to right click in an empty area in any of the other “bar” areas, this is best done to the right of the current page tab. Then select “Menu Bar” from the drop down.
OS X – Keychain
- Go to Applications
- Select Utilities
- Select Keychain Access
- Double click the CA in X509Anchors (Tiger) or System Roots (Leopard)
- In the “Trusts” section, change the trust to “Never Trust”

OS X Keychain Trust Options
For a better guide on accessing OS X items please refer to Laura’s original posting as I don’t have updated screenshots (She’s got the only Mac in-house).
Now you should be able to keep tabs on what trusts are being granted to each CA. In general, you should monitor what trusts you are allowing on your CAs anyway, but with the recent events of the MD5 collapse, it only helps to be a little more proactive.
Each Tuesday, Security Musings features a topic to help educate our readers about security. For more information about Gemini Security Solutions’ security education capabilities, contact us!





