Re: https confusion



On Sat, 08 Apr 2006 22:50:06 GMT, Peter Pearson wrote:
On Fri, 07 Apr 2006 18:45:09 -0700, Todd wrote:
[snip]

The idea behind the customer's request is that
he only wants his road warriors to access the
site and only with encryption.

Can someone point me to a explanation of how https
works? Is https the correct route to go?

Hey, Wikipedia has a pretty decent entry on HTTPS, which
says, in part,

[snip]

Two additional comforting observations:

1. Figure 1 at
http://httpd.apache.org/docs-2.0/ssl/ssl_intro.html
shows where in the SSL protocol the server gets a
chance to ask the client for a certificate. SSL
(essentially the same as TLS) is the secure-session
protocol on which HTTPS is built.

2. The Firefox browser I'm running, under
Edit / Preferences / Advanced / Certificates,
has a box labelled "Client Certificate Selection" to
"Decide how Firefox selects a security certificate to
present to web sites that require one." Sounds like
exactly what Todd needs.

--
To email me, substitute nowhere->spamcop, invalid->net.
.



Relevant Pages

  • Re: Tomcat SSL servlet
    ... >>and Mozilla1.6 both show me info about certificate and I accept, ... >>status icon is shown, if i click where it should be the icon, IE show me ... the page with https but something like an image is specifying a URL ...
    (comp.lang.java.programmer)
  • IE https certificate attack
    ... A flaw in Microsoft Internet Explorer allows an attacker to perform ... server name with the name stored in the certificate. ... There is a flaw in the way IE checks HTTPS objects that are embedded into ... I don't know the source code of the Internet Explorer I cannot check the ...
    (Bugtraq)
  • Re: IE https certificate attack
    ... How non-interactive ssl clients in EAI and web services software handle ... Subject: IE https certificate attack ...
    (Vuln-Dev)
  • [NT] Internet Explore HTTPS Certificate Attack
    ... A flaw in Microsoft Internet Explorer allows an attacker to perform a SSL ... There is a flaw in the way Internet Explorer checks HTTPS objects that are ... Explorer does only check if the certificate of the HTTPS server is ... Internet Explorer will only check if the cert was signed by a trusted CA ...
    (Securiteam)
  • RE: Outlook HTTPS over RPC error - Inconsistent users
    ... If the clients are using Outlook with PRC over HTTP and issue ONLY occurs ... issue which means it might be a client Outlook configuration or workstation ... over HTTPS because there is a problem with the certificate assigned to the ... With RPC over HTTPS no such pop up ...
    (microsoft.public.windows.server.sbs)