Alex,,
The trouble with using self signed certs is that you need to install the CA
cert in the browser to stop messages popping up when you connect to the site -
obviously no real problem as you will either be using them for testing or in a
closed environment (or limited number of clients). Using the 'Free Test
Certificates' from thawte is a little better as the CA cert that they use to
sign the CSR is already installed in Netscape (only 4.7x?).
Karl,
To avoid this problem 'buy a cert' or install the CA cert into each browser
(have a look at pkg.contrib/loadcacert.cgi)
Mikey
"Alex C. Koch" <[EMAIL PROTECTED]> on 02/03/2000 19:11:58
Please respond to [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
cc: (bcc: Mike Innes/Virgin Direct/GB)
Subject: Re: Certificate questions...
Is getting one of these test certificate better than using a self signed
test certificate that can be generated with openSSL? I am currently using
a certificate that I generated myself. What would the advantages be of
using a certificate from Thawte when it is not authenticated by them?
At 11:42 AM 3/2/00 -0600, you wrote:
>Hi folks,
>
>I have built the MODSSL package and Apache, and it works. I got a
>"test" certificate from Thawte (their "unauthenticated" one) and it
>installed and worked properly.
Alex Koch
[EMAIL PROTECTED]
https://128.253.163.111 (SSL secured)
http://home.adelphia.net/~alexk
<<-- PGP Keys -->>
2048 bit RSA key id: 0x58635D8F
4096 bit DH/DSS key id: 0x0784EFC5
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]
********************************************************************************
Internet communications are not secure. This message is confidential to the intended
addressee. Any copying or distribution of it by anyone without the addressee's consent
may be unlawful. If you are not the intended addressee, please inform us immediately
and then delete this message.
Virgin Direct Personal Financial Service Ltd is regulated by the Personal Investment
Authority for life insurance, pension and unit trust business and represents only the
Virgin Direct marketing group. Registered office: Discovery House, Whiting Road,
Norwich NR4 6EJ, UK. Registered in England No. 3072766.
The Virgin One account is a secured personal bank account with The Royal Bank of
Scotland plc. It is provided by Virgin Direct Personal Finance Ltd which is a
representative only of Virgin Direct Personal Financial Service Ltd. Registered
office: Waterhouse Square, 138-142 Holborn, London EC1N 2TH, UK. Registered in England
no 3414708.
The Virgin Deposit Account is a personal deposit account with The Royal Bank of
Scotland plc administered by Virgin Direct Personal Financial Service Ltd.
********************************************************************************
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]