Menu

#10 SSL root CA check

open
nobody
None
5
2009-05-26
2009-05-26
No

Hi. There's a spiffy certificate authority out there that gives out free class 1 certificates. startssl.com
They're trusted by mozilla/firefox as a legitimate root CA authority (if your certs are up to date. Not yet with Microsoft)

So now I'm able to (and I have) signed the certificate for my MUCK at telnets://latitude.muck.ca:992

I'm not sure if tinyfugue can do this already or not, but I'd like to request to be able to verify the root authority in tinyfugue with openssl (Which on my system is configured to look in /etc/ssl/certs for trusted root certificates), and ensure the certificate is up to date and otherwise valid (and preferably even check for CRL revokations).

This would protect me from man-in-the-middle attacks while connecting to my MUCK :)

Discussion


Log in to post a comment.