On Thu, Sep 27, 2007 at 11:38:39AM -0700, David Schwartz wrote: > > considered as proposition to discussion. Real, secure programming should > > be based on existing, well checked protocols (which is possible in this > > case). > > The OP was going to embed his CA's private key in his installer.
The OP was not thinking clearly about key management. My first response to the OP outlined what needs to be done for key-management (a human assisted enrollment process). -- Viktor. ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager [EMAIL PROTECTED]