Menu

#44 SSL does not authenticate remote hostname

open
nobody
None
5
2009-02-20
2009-02-20
Anonymous
No

Whilst certificates are checked against the relevant root CA signatures, there's no obvious way of making sure that the SSL certificate has been assigned to the correct server. The example doesn't seem to do this.

If there is no way of fixing this it mean asio's SSL is prone to man-in-the-middle attacks.

If there is a way of doing this, an example would be handy.

Discussion


Log in to post a comment.