[Info-vax] Certificates

Gary Sparkes mokuba at gmail.com
Mon Sep 11 17:11:04 EDT 2023


On Monday, September 11, 2023 at 4:50:57 PM UTC-4, gah4 wrote:
> On Monday, September 11, 2023 at 1:12:17 PM UTC-7, Gary Sparkes wrote: 
> 
> (snip)
> > All internet SSL certificates are worth is identifying the remote host 
> > (assuming no private key compromise) and encrypting traffic 
> > between the two. They imply or do nothing else.
> They are needed to avoid "man in the middle" attacks. 
> 

That's precisely the point I was trying to make  - that's all they're good for. 

Identify the machine - "Is this the host I want to connect to?"

Encrypt the traffic between you and the machine - 
"I know who i'm talking to now, and no one can read this and we
can detect if it's been modified(invalid data)/intercepted
(certificate changes)"



More information about the Info-vax mailing list