[ale] https

Geoffrey esoteric at 3times25.net
Wed Feb 13 14:17:39 EST 2002


Denny Chambers wrote:
> Here is a link to the modssl userguide, which talks about creating your
> own self sign certificates. This will work on your ssl server, although
> this method is not as secure as having a real certificate from a CA. On
> the other hand this is a lot cheaper.

Correct me if I'm wrong, but the security of a self signed certificate 
is no less then the security of a purchased one.  The only difference is 
that folks visiting your site might feel more comfortable finding the 
certificate is signed by one of the well known certificate rapists, 
rather then being signed by 'joe the web guy.'

-- 
Until later: Geoffrey		esoteric at 3times25.net

"...the system (Microsoft passport) carries significant risks to users that
are not made adequately clear in the technical documentation available."
- David P. Kormann and Aviel D. Rubin, AT&T Labs - Research
- http://www.avirubin.com/passport.html


---
This message has been sent through the ALE general discussion list.
See http://www.ale.org/mailing-lists.shtml for more info. Problems should be 
sent to listmaster at ale dot org.






More information about the Ale mailing list