Re: Still missing: TLS_ECDH_anon_WITH_AES_xxx_GCM_SHAxxx
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.tls,gmane.ietf.secsh |
|---|---|
| Message-ID | <9A043F3CF02CD34C8E74AC1594475C737238AD92@uxcn10-6.UoA.auckland.ac.nz> |
Daniel Kahn Gillmor <[email protected]> writes: >0) either the software or the admin must manually provision the certificate >for the server; this means making decisions about questions that don't >necessarily have any good answers, which is not a situation you want your >users to be in. Servers operating in a pool now need to have some sort of >secret key distribution mechanism, for example. One option for this is for the server to auto-generate the cert on first install/setup. The alternative that's currently used on way too many devices is for them to have a pre-generated generic cert with incorrect ID information with the private key shared across all devices. Peter.