> I have an application that is wanting me to add an OpenSSL certificate
> to my server, but the application will be communicating server-to-server
> over SSL.  Therefore, the browser "problem" won't be one, right?

        This is actually a very complex question, and anyone who answers it 
without
first asking you what your application is and what threats it needs to
protect against is doing you a disservice.

        The purpose of a third-party certificate is to validate the identity of 
the
endpoint presenting that certificate. Whether or not you need this depends
upon:

        1) Do you need to validate the identity of the endpoint?

        2) Is testing for a certificate from a trusted third party sufficient? 
(Do
we trust them enough? How secure do we need to be?)

        3) Do we have any other way to validate the endpoint? For example, can 
we
embed its public key in the application?

        DS


______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to