Re: cert file location

Gerrit Pape <[email protected]>
Newsgroups gmane.comp.misc.pape.general
Message-ID <[email protected]>
On Fri, May 21, 2004 at 06:31:23PM +0200, Clemens Fischer wrote:
> * 2004-05-05 Gerrit Pape:
> > On Tue, May 04, 2004 at 08:43:09PM +0200, Lukas Beeler wrote:
> >> I would vote for certificates outside of the chroot, just for the sake
> >> of lazyness.
> > But yours aren't strong either: compromised vs compromised, and laziness.
> > Hm, I'm not yet convinced.
> (i hope this hasn't yet changed in 0.9.1 yet.)

Just to be clear, currently the sslio program first changes the root
directory and drops permissions, then it reads the key files.  The
documentation now explicitly states this.

> seen from the initialization chain, users must assume a safe environment
> from where to start.  *I* would much prefer keeping key material outside
> the jail, again assuming its parent is (was) safe.

I'm sorry I don't understand your argument.  Why would you prefer that?

> gerrit, do you think matrx-ssl will be available on freebsd soon?  i tried

I don't think it's that difficult to port it to freebsd, the source
seems to support porting well.  It's just that someone would have to do
it.

Regards, Gerrit.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.