Re: RFC: Proposal: Install a /etc/ssl/cert.pem by default?

看板FB_security作者時間11年前 (2014/07/04 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串14/29 (看更多)
There is always going to be skepticism about who to trust by default. The CA system is out of control and it worries me as well. However, if we do not make an effort to provide a default trust store why do we enforce verification by default? I feel it would be more consistent to disable verification requiring those who know what they're doing to create their own trust store and pass --verify-peer to fetch manually. I'm on the verge of breaking my keyboard every time I jump onto a random FreeBSD server and try to fetch something over https. --no-verify-peer is now muscle memory; that isn't a good sign. I eagerly await verification through DNSSEC to take off. -2c _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1JjPfWMW (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 14 之 29 篇):
文章代碼(AID): #1JjPfWMW (FB_security)