... may be a dumb question ?

From: Michael Gale (michael_at_bluesuperman.com)
Date: 12/31/03

  • Next message: Charles Smith: "Re: Cryptography/Cryptanalysis"
    Date: Tue, 30 Dec 2003 22:35:17 -0700
    To: security-basics@securityfocus.com
    
    

    Hello,

            I have a question, I want to make a secure web site for me and a few
    people. So this is my crazy design.

    I setup Apache with PHP and am using mod_ssl. I created my own CA on a
    linux box. I then created a CSR for the web server and
    signed it with my CA.

    Now I give all the people I want to have access to the site my ca.crt
    and they import it into their browser. So now there browser will accept
    my site's cert :) with out the warning.

    Now if they are running a linux / unix box I can have them create a CSR
    and have my CA sign it. Then they can import that cert into their
    browser.

    Now if I understand it correctly when the client accesses my site the
    server and client will exchange certs and trust each other :) unless I
    add the user to the CRL.

    The rest of the traffic will be over SSL ... so is this a secure way of
    allows access to a directory ?

    Do you see any problems ?

    -- 
    Hand over the Slackware CD's and back AWAY from the computer, your geek
    rights have been revoked !!!
    Michael Gale
    Slackware user :)
    Bluesuperman.com 
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Charles Smith: "Re: Cryptography/Cryptanalysis"

    Relevant Pages

    • Re: ... may be a dumb question ?
      ... >and they import it into their browser. ... >Now if they are running a linux / unix box I can have them create a CSR ... Then they can import that cert into their ... >Now if I understand it correctly when the client accesses my site the ...
      (Security-Basics)
    • Re: HTTPS proxy tool that resigns SSL certs
      ... having access to import a certificate into the browser. ... Your approach won't work, since your cert for attacker.com will most likely never match the URL that the victim's browser is expecting, and they will get a warning. ... Everything hinges on your being able to get a cert THAT MATCHES THE SITE THAT THE VICTIM IS GOING TO signed with a key that the browser will accept and valid for the current date. ... Compromise a recognised CA's verification checks to convince them to issue you a certificate for the target site. ...
      (Pen-Test)
    • Re: Several questions about the LG Voyager
      ... thing has got iPhone-style WebTV browser device written all over it. ... attaches to without a sellphone company interference. ... file off the main computer on the tablet far away, ... N800 or N810 Linux internet tablet the sellphone company DOESN'T get to ...
      (alt.cellular.verizon)
    • Re: Reporting tools
      ... I always find it a little suspect when people mention "linux" in context ... It's not that simple because .NET is a local Windows service and client ... a browser connects to the server and identifies the ... Of course you can do this in any language: ...
      (comp.databases.pick)
    • Re: Linux still surfs slower than Windows
      ... That wouldn't explain why the Linux browser chokes on any given ... >>up with the same DNS configurations. ... > although it seems they do work properly with MS requests. ...
      (comp.os.linux.networking)