[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: SSL client certificate question and bdb_dn2id_matched question



Search the archives.
http://www.openldap.org/lists/openldap-software/200205/msg00043.html
http://www.openldap.org/lists/openldap-software/200207/msg00063.html

  -- Howard Chu
  Chief Architect, Symas Corp.       Director, Highland Sun
  http://www.symas.com               http://highlandsun.com/hyc
  Symas: Premier OpenSource Development and Support 

> -----Original Message-----
> From: owner-openldap-software@OpenLDAP.org
> [mailto:owner-openldap-software@OpenLDAP.org]On Behalf Of Bradley Scutvick

> 
> Howard Chu wrote:
> > Self-signed certs can be made to work, but should not be 
> used. They are a
> > security liability. Please read the admin guide:
> > http://www.openldap.org/doc/admin21/tls.html
> 
> Is it a security liability just because no institution is 
> vouching for 
> your identity or does it undermine the encryption somehow?  I 
> know it's 
> off topic, ignore as you please.
> 
> -Brad
> 
>