Winged Wolf wrote:
> 
> I'm going to go out on a limb here and point everyone at Bruce Schneier's
> paper:
> 
> http://www.counterpane.com/pki-risks.html

Yup, read it.  I never was really much into trusting Verisign, Thawte,
etc; however when YOU run the henhouse (eg. roll your own CA in-house,
and secure things top-to-bottom in a manner you deem "good enough")
there is a good deal more assurance.  I've never once dealt with a
public CA and don't plan to start now.

-- 

     "I'm in it for the fun, but it's more fun when you win!"

                                            --Michael Roeder
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to