Re: Firewall best practices

"Marcus J. Ranum" <[email protected]> Wed, 28 Apr 2010 15:28:04 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
ArkanoiD wrote:
> The problem is, it doesn't necessary needs to be root CA.

Everyone forgets that SSL was only really intended to solve a
fairly limited problem. That problem being, namely, "how can
Verisign and RSA monetize their patents on PKI?" - if you
want to understand why SSL is the way it is, you need to consider
what it was designed to do; then everything makes sense.
As I said earlier, I'm boggled that nobody has fixed it.
Consider that a measure of how much standards bodies are
really worth and how much customers care.

mjr.
-- 
Marcus J. Ranum		CSO, Tenable Network Security, Inc.
			http://www.tenablesecurity.com