RE: CERTIFICATE



Encryption and authentication are independent of each other.

Holding a valid certificate says that the signing authority (e.g.
Verisign) attests that you (i.e. the web server servicing your site) are
who you claim to be. Conversely if your certificate is not accepted by
your browser (due to name conflict, expiration, or revocation) your
identity is in question.

But if you accept the invalid certificate, the server and client will
still utilize HTTPS based on whatever configuration they can negotiate.
So yes the data will still by encrypted. If you want to see this in
action, fire up wireshark.

Other uses of certificates may get a little more complicated. For
example if you use certificates to authenticate to VPN, an expired cert
will prevent you from getting onto the VPN. But in that case you are
still not running cleartext - you are just not running at all.

Terry

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of anon@xxxxxxxxx
Sent: Monday, January 28, 2008 1:28 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: CERTIFICATE

could someone tell me what would happen to encrypted traffic if you have
an expired certificate?? Does the traffic flow in clear text
henceforth?? or just that the credebility of traffic from that source
cannot be accounted for??



Relevant Pages

  • Re: What can WPA/WPA2 use for Encryption
    ... WPA2 can only use AES/CCMP for the encryption but you can use various ... EAP methods for a more secure authentication setup. ... If this is a point-to-point connection that is not intended to accept ... Securing Apache Web Server with thawte Digital Certificate ...
    (Security-Basics)
  • Secure website - explanation required.
    ... I'm in need of an explanation of secure websites and authenticated ... certificate. ... the authentication is also encrypted - the "pro" version uses a longer ... encryption for the authentication. ...
    (microsoft.public.inetserver.misc)
  • Secure website - explanation required.
    ... I'm in need of an explanation of secure websites and authenticated ... certificate. ... the authentication is also encrypted - the "pro" version uses a longer ... encryption for the authentication. ...
    (microsoft.public.inetserver.iis)
  • Secure website - explanation required.
    ... I'm in need of an explanation of secure websites and authenticated ... certificate. ... the authentication is also encrypted - the "pro" version uses a longer ... encryption for the authentication. ...
    (microsoft.public.inetserver.iis.security)
  • RE: Questions regarding EFS
    ... Actually, it's not at all like adding a recovery agent, nor is the ... UserBob has an EFS certificate. ... Symmetric keys are used for file encryption ... Option 1- UserBob has UserJoe log on to Ripped2 and create a file, ...
    (Focus-Microsoft)