OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Garrett Wollman (wollmankhavrinen.lcs.mit.edu)
Date: Sun Jan 07 2001 - 13:25:35 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    <<On Sun, 7 Jan 2001 11:21:16 -0500 (EST), Robert Watson <rwatsonFreeBSD.ORG> said:

    > an SSL telnet does offer something that SSH does not have: the ability to
    > connect to a new host without a manual keying procedure.

    Some people would say that this is a liability. I've got a number of
    particularly argumentative users here who insist that trusted third
    parties of any kind are fundamentally bad. While I don't necessarily
    agree, it is true that in any X.509 configuration it is necessary to
    be very careful about which CAs one trusts and for which purposes.
    (For our SSL applications here, we will only trust our own CA, since
    it is the only one capable of authenticating our users.)

    -GAWollman

    To Unsubscribe: send mail to majordomoFreeBSD.org
    with "unsubscribe freebsd-security" in the body of the message