Re: Still missing: TLS_ECDH_anon_WITH_AES_xxx_GCM_SHAxxx

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.tls,gmane.ietf.secsh
Message-ID <9A043F3CF02CD34C8E74AC1594475C737238AD92@uxcn10-6.UoA.auckland.ac.nz>
Daniel Kahn Gillmor <[email protected]> writes:

>0) either the software or the admin must manually provision the certificate
>for the server; this means making decisions about questions that don't
>necessarily have any good answers, which is not a situation you want your
>users to be in.  Servers operating in a pool now need to have some sort of
>secret key distribution mechanism, for example.

One option for this is for the server to auto-generate the cert on first
install/setup.  The alternative that's currently used on way too many devices
is for them to have a pre-generated generic cert with incorrect ID information
with the private key shared across all devices.

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.