Re: [cryptography] server-signed client certs (Re: SSL is not "broken by design")

2011-09-26 Thread Thierry Moreau
ianG wrote: On 26/09/11 16:49 PM, Adam Back wrote: What about introducing the concept of server signed client certs. A server could recognize its own server key pair signature on the client cert, even though the server cert is not a proper CA cert. Hmmm... interesting idea! The term I us

Re: [cryptography] server-signed client certs (Re: SSL is not "broken by design")

2011-09-26 Thread ianG
On 26/09/11 16:49 PM, Adam Back wrote: What about introducing the concept of server signed client certs. A server could recognize its own server key pair signature on the client cert, even though the server cert is not a proper CA cert. Hmmm... interesting idea! Typically, the server applic

[cryptography] server-signed client certs (Re: SSL is not "broken by design")

2011-09-25 Thread Adam Back
What about introducing the concept of server signed client certs. A server could recognize its own server key pair signature on the client cert, even though the server cert is not a proper CA cert. Then the password request on the client goes to the browser/os key store. So long as you had CA p