Re: RFC: Proposal: Install a /etc/ssl/cert.pem by default?

看板FB_security作者時間11年前 (2014/07/03 10:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串5/29 (看更多)
On 07/03/14 03:47, Eitan Adler: > IMHO, it is sane to follow the same policy that Mozilla follows and to > use their root store by default. It's policy define very generic requirements only. Almost anyone can apply. But I'm not going to discuss Mozila's policy here beyond my opinion that it's definition of "trusted" is near to meaningless. >> If I consider a CA to be trustworthy, I will insert it's certificate to >> trusted store. No one is welcomed to make such decision in behalf of me. > > So remove or edit the defaults. Be sure I'm doing it already with browsers stores. But I wish system/program shall be safe by default because not all users are experts that can recognize dangerous defaults. Are you ready to recommend a CA as trustworthy and take responsibility for such advice ? OK, I expressed my personal opinion in full and I'm not wishing to start a flame war here ;-) Cheers Dan _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1JjC2Ylr (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 5 之 29 篇):
文章代碼(AID): #1JjC2Ylr (FB_security)