hi,
   last time i checked it sends the results as your auth cert.. you do 
need to enter a passphrase or cache it to produce the unique result that
is shuttled to the server. this is the means used to verify you are who 
you say you are.. what you have, and what you know..  hmmm...
which means that if doing this on a person to person basis it is only 
as secure as your desktop..;-)) if you think about it is quite simular to 
what ssh does with RSA to authenticate.. just the technology is 
diff.
                                Regards,
                                                [EMAIL PROTECTED]
> From my understanding, the client cert is transmitted in clear.
> When server receives the client cert, server verifies the client
> cert using a CA (or chained CAs), like verifying the date, signature,
> etc. The question I have is that whoever could intercepts the client
> cert could fake the client. Am I right?
> 
> Thanks.
> --Yunhong
_________________________

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to