[Info-vax] Certificates
    Gary Sparkes 
    mokuba at gmail.com
       
    Mon Sep 11 17:11:04 EDT 2023
    
    
  
On Monday, September 11, 2023 at 4:50:57 PM UTC-4, gah4 wrote:
> On Monday, September 11, 2023 at 1:12:17 PM UTC-7, Gary Sparkes wrote: 
> 
> (snip)
> > All internet SSL certificates are worth is identifying the remote host 
> > (assuming no private key compromise) and encrypting traffic 
> > between the two. They imply or do nothing else.
> They are needed to avoid "man in the middle" attacks. 
> 
That's precisely the point I was trying to make  - that's all they're good for. 
Identify the machine - "Is this the host I want to connect to?"
Encrypt the traffic between you and the machine - 
"I know who i'm talking to now, and no one can read this and we
can detect if it's been modified(invalid data)/intercepted
(certificate changes)"
    
    
More information about the Info-vax
mailing list