>>>>> "David" == David Lang <[EMAIL PROTECTED]> writes:

David> John, I have 600 sites, each with their own key/cert and 16 servers (soon
David> to be 32 servers) how can I possibly plan on entering the passphrase in
David> for each site on each server on startup?

You hire more people, and avoid re-boots. Security has a definite,
measurable, cost.

If you _don't_ use a passphrase, anyone who breaks into your server can then
impersonate it.

Do the risk/reward/cost analysis, and see if it makes sense for you or not.

Of course, you could also use a hardware key store, and unlock that
instead. And perhaps charge more for the increased security.

-- 
Carson Gaspar -- [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED]
http://www.cs.columbia.edu/~carson/home.html
Queen Trapped in a Butch Body
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to