Re: cert file location
"Clemens Fischer" <[email protected]>
| Newsgroups | gmane.comp.misc.pape.general |
|---|---|
| Message-ID | <[email protected]> |
* 2004-05-05 Gerrit Pape: > On Tue, May 04, 2004 at 08:43:09PM +0200, Lukas Beeler wrote: >> I would vote for certificates outside of the chroot, just for the sake >> of lazyness. > > But yours aren't strong either: compromised vs compromised, and laziness. > Hm, I'm not yet convinced. (i hope this hasn't yet changed in 0.9.1 yet.) seen from the initialization chain, users must assume a safe environment from where to start. *I* would much prefer keeping key material outside the jail, again assuming its parent is (was) safe. gerrit, do you think matrx-ssl will be available on freebsd soon? i tried to contact them about doing a port without an answer. this might have to do with their broken CGIs, though. clemens