LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 02-08-2012, 11:45 AM   #1
lanman777
LQ Newbie
 
Registered: Feb 2012
Posts: 2

Rep: Reputation: Disabled
Creating an SSL Certificate


I have a customer that has an unusual request. the want a V2 certificate?
Is there such a thing? All my certificates have been V3.
So can I create a V2 certificate with something like certutil or another tool?
Is it even possible?
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 02-09-2012, 11:36 AM   #2
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 159

Rep: Reputation: 53
SSL v2 hasn't seen widespread use since v3 came out in 1996 to address serious security flaws in the prior version. Enabling v2 protocol allows people using older browsers to connect to your site, however, those transactions are less secure and, should it matter, such a site cannot achieve PCI compliance. SSL v2 is disabled or non existent in IE 7+, Firefox 2+, Opera and Safari. Any site needing to use SSL/TLS should not be using the old protocol. In fact, the latest version of TLS will not function with SSL v2 at all.
 
2 members found this post helpful.
Old 02-10-2012, 08:15 AM   #3
sundialsvcs
Senior Member
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 3,685

Rep: Reputation: 330Reputation: 330Reputation: 330Reputation: 330
I agree with NyteOwl and suggest that you should take this post, along with some supporting material (which NiteOwl may be able to provide?) to explain to your client why, "no, you really don't want a V2 certificate, and here is why."

You do not want to weaken the cryptographic security of your site just to accommodate "a particularly loud-mouthed Luddite who buys an occasional toaster from you now and then." They're out there, all right ... still using Windows 95...

(Actually, now that you mention it, I did hear of one company that cooked up a very creative solution to deal with one old scrotch of a client who did place big orders. They set up "a special web-site just for him," which was simply a secure proxy to their real site. They customized the templates for the "personal" site to stroke the guy's ego, but all the site actually did was to immediately re-encrypt and re-transmit.

Last edited by sundialsvcs; 02-10-2012 at 08:17 AM.
 
Old 02-10-2012, 09:24 AM   #4
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 342

Rep: Reputation: 38
does the customer have a reason for "v2", do they even know what that means? maybe they though v2 was better because it is a step above v1 ???
 
Old 02-10-2012, 10:32 AM   #5
lanman777
LQ Newbie
 
Registered: Feb 2012
Posts: 2

Original Poster
Rep: Reputation: Disabled
My guess is the api for some old solution they are using. Probably requiring CryptoAPI used by v2 instead of CNG used by V3.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to import/use CAcert SSL root certificate to use SSL with Xchat IRC client? GrapefruiTgirl Linux - Software 9 04-05-2011 09:54 AM
Creating a formal SSL certificate for Fedora issued by Geocerts fedora.brett Linux - Newbie 1 12-08-2010 10:24 PM
Apache with SSL does not load the 2nd SSL certificate janstapel Linux - Newbie 1 06-17-2010 09:32 PM
Problem Creating Apache SSL Certificate kaplan71 Linux - Software 0 12-27-2005 12:52 PM
Creating an email certificate using SSL? jmnovak Linux - Software 0 04-29-2003 09:22 PM


All times are GMT -5. The time now is 05:27 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration