Bug#639744: Compromised certificates for *.google.com issued by DigiNotar Root CA

On mar., 2011-08-30 at 22:48 +0200, Mike Hommey wrote:
> 1. Several fraudulent certificates whose fingerprint is unknown signed
> with several different intermediate certs that are cross-signed by other
> "safe" CAs (aiui). 

I missed that. What is the source for that? (i looked at the mozilla bug
earlier but it lacks that level of precision)

