Re: On CertificateFile and SystemCertificates

2016-06-12 Thread Oswald Buddenhagen
On Sun, Jun 12, 2016 at 06:18:30PM +0200, Yuri D'Elia wrote: > I'd argue that when CertificateFile is specified, SystemCertificates > should default to no. > makes sense. -- What NetFlow Analyzer can do for you? Monitors

On CertificateFile and SystemCertificates

2016-06-12 Thread Yuri D'Elia
Some thoughts on CertificateFile. I'd argue that when CertificateFile is specified, SystemCertificates should default to no. The reasoning is that when you use CertificateFile you probably want certificate/key pinning, but this is not what happens. If SystemCertificates is yes, your (self-signed)