Re: Transfer from one server to another, compress and digest

Antonio Quartulli <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On 03/01/2024 20:03, Gert Doering wrote:
> Not sure I can come up with a good attack scenario
> in an OpenVPN PKI scenario where the CA would be stopped from doing
> something nasty by doing the full .csr dance (because it could still just
> create arbitrary .key/.crt on its own, thus getting access to the VPN
> server).

I think the .csr dance would prevent the CA from impersonating well 
known users with a well known certificate.

Cheers,

-- 
Antonio Quartulli
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.