Re: Installation instructions
Hunter Matthews <[email protected]> 02 Feb 2003 17:04:43 -0500
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <[email protected]> |
up2date contains much careful code to insure that not only is the link
encrypted, but it was encrypted with a certificate signed by the
RHNS-CA-CERT. Thats WHY each client has a copy of the CA-CERT - it
wouldn't be needed if encryption was the only goal.
So snake oit isn't important. No, I can't imagine someone spoofing my
current server (or yours, or anyones) server either. But I can't imagine
why that idiot tried DOS'ing my web server the other day either.
On Sat, 2003-02-01 at 16:06, Jonathan S. Shapiro wrote:
> On Sat, 2003-02-01 at 14:53, John Berninger wrote:
> > Jonathan -
> >
> > The snakeoil.crt certificate is designed only for limited
> > testing; the mod_ssl docs and Apache docs recommend that this
> > certificate not be used in any sort of production or even
> > pseudo-production environment.
>
> I agree, and see my later correction.
>
> However, the server.{crt,key} generated by mod_ssl are freshly generated
> for each server. If all we are after is link encryption rather than
> mutual authentication, those ought to be okay to use.
>
> shap
>
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
>
>
--
Hunter Matthews Unix / Network Administrator
Office: BioScience 145/244 Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.