Re: cert file location
Gerrit Pape <[email protected]>
| Newsgroups | gmane.comp.misc.pape.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, May 21, 2004 at 06:31:23PM +0200, Clemens Fischer wrote: > * 2004-05-05 Gerrit Pape: > > On Tue, May 04, 2004 at 08:43:09PM +0200, Lukas Beeler wrote: > >> I would vote for certificates outside of the chroot, just for the sake > >> of lazyness. > > But yours aren't strong either: compromised vs compromised, and laziness. > > Hm, I'm not yet convinced. > (i hope this hasn't yet changed in 0.9.1 yet.) Just to be clear, currently the sslio program first changes the root directory and drops permissions, then it reads the key files. The documentation now explicitly states this. > seen from the initialization chain, users must assume a safe environment > from where to start. *I* would much prefer keeping key material outside > the jail, again assuming its parent is (was) safe. I'm sorry I don't understand your argument. Why would you prefer that? > gerrit, do you think matrx-ssl will be available on freebsd soon? i tried I don't think it's that difficult to port it to freebsd, the source seems to support porting well. It's just that someone would have to do it. Regards, Gerrit.