Re: WAS: Bittorrent - utorrent NOW: Certificate Talk



Tremaine Lea wrote:
Having said that, the BCSG *will* refuse self-signed certs and expired
certs etc.


That is the stupidest thing I've ever heard. Honestly, a paid-for cert
is barely more trustworthy than a self-signed cert. The entire cert
system is broken by design, and benefits nobody but the money collectors
at the major companies (VeriSign, Entrust, etc).

Can somebody convince me that my understanding is mistaken?

Thanks,
Randy

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Trying to connect to Active Directory via LDAPS
    ... I have a need to connect securely to AD via LDAP. ... My AD Server appears to have both a self-signed cert and a purchased cert ...
    (microsoft.public.windows.server.active_directory)
  • Outlook anywhere & ecert
    ... CA cert was installed to replace self-signed cert. ... OWA and ActiveSync are OK ... Outlook anywhere is not ok. ...
    (microsoft.public.exchange.connectivity)
  • Re: Web certificates
    ... Don't issue a self-signed cert. ... I'd recommend purchasing one ... on both the ISA server and your Exchange Front-end server. ...
    (microsoft.public.exchange.admin)
  • Re: z/OS SSL
    ... I _thought_ I was creating a self-signed cert. ... did on our z/VM systems for testing. ... For IBM-MAIN subscribe / signoff / archive access instructions, ...
    (bit.listserv.ibm-main)
  • Re: SSL Cert on SMTP
    ... I enabled SMTP on the 3rd part cert and when I run get-exchangecertificate, ... Exchange is using the self-signed cert and not the 3rd party cert. ...
    (microsoft.public.exchange.admin)