Re: Firewall best practices
"Marcus J. Ranum" <[email protected]> Wed, 28 Apr 2010 15:28:04 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
ArkanoiD wrote: > The problem is, it doesn't necessary needs to be root CA. Everyone forgets that SSL was only really intended to solve a fairly limited problem. That problem being, namely, "how can Verisign and RSA monetize their patents on PKI?" - if you want to understand why SSL is the way it is, you need to consider what it was designed to do; then everything makes sense. As I said earlier, I'm boggled that nobody has fixed it. Consider that a measure of how much standards bodies are really worth and how much customers care. mjr. -- Marcus J. Ranum CSO, Tenable Network Security, Inc. http://www.tenablesecurity.com