Re: cert file location (was Re: sslio documentation clarification (Re: ipsvd-0.9.0 available))
Gerrit Pape <[email protected]>
| Newsgroups | gmane.comp.misc.pape.general |
|---|---|
| Message-ID | <[email protected]> |
On Tue, May 04, 2004 at 08:43:09PM +0200, Lukas Beeler wrote: > * Charlie Brady <[email protected]>: > > True. It's probably a little easier to steal the content of readable files > > than from somewhere in process memory. There's not going to be a fork/exec > Compromised is compromised. It doesnt really matter if the Yes, I concur. > > Understood. But is the matrixSSL library really likely to be under attack > > via the content of the certificate/key files? I knew my argument was weak. > I would vote for certificates outside of the chroot, just for the > sake of lazyness. But yours aren't strong either: compromised vs compromised, and laziness. Hm, I'm not yet convinced. Regards, Gerrit.