OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Slightly OT: SSL certs - best practice?

From: Peter Jeremy (peterjeremyoptushome.com.au)
Date: Tue May 16 2006 - 04:15:12 CDT


On Mon, 2006-May-15 23:53:03 +0100, James O'Gorman wrote:
>PS - Once I've worked out how exactly I'm supposed to be doing this,
>I'll probably get some "officially" signed certs. I hear CACert are a
>good, free way of doing this. Anyone got any comments on that?

I've gone through the CAcert assurance process and it seems to work,
though a lot depends on your access to other assurers. Note that the
CAcert certificates are now part of ports/security/ca-roots though the
issue of bootstrapping remains (how do you know that your roots file
is genuine).

--
Peter Jeremy

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (FreeBSD)

iD8DBQFEaZgf/opHv/APuIcRAm8WAJ9YozyKpoGVRNj0HOjYWo9fizAGXQCggPx1
aEjrl8pyT3kpndgBMiWOB0A=
=C5j3
-----END PGP SIGNATURE-----