LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-06-2014, 06:29 AM   #1
Armann
Member
 
Registered: May 2013
Location: Iceland
Distribution: RHEL/Fedora
Posts: 38

Rep: Reputation: Disabled
Question SS ssl, cannot contact ca, encrypted ?


Hi, I have a question about self signed certs.
If there is no CA for it or the CA does not answer is the traffic encrypted ?

Thanks.
 
Old 10-07-2014, 12:54 AM   #2
sag47
Senior Member
 
Registered: Sep 2009
Location: Raleigh, NC
Distribution: Ubuntu, PopOS, Raspbian
Posts: 1,899
Blog Entries: 36

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
Short answer is yes, the connection is still encrypted with self signed certificates.

Allow me to clarify a few things about SSL CAs. A certificate authority is not a listening service like a web server. It is simply a certificate that signs other certificates. So when you have a certificate authority certificate installed in your browser it can be used to verify all of the certs it has signed.

If you don't have a certificate authority certificate installed in your browser (or you delete a CA cert from your browser) then it will show up with a certificate warning just like a self signed cert.

If you'd like to play a bit with a certificate authority I have a set of scripts for an internal CA that I run at home.

https://github.com/samrocketman/my_internal_ca

Does that help to explain a little bit? I understand that most classes that discuss SSL explain certificate authorities like they're network services taking connections but that's fundamentally wrong. I say that because when I first learned about CA's I had the same misunderstanding.
 
1 members found this post helpful.
Old 10-07-2014, 06:02 PM   #3
Armann
Member
 
Registered: May 2013
Location: Iceland
Distribution: RHEL/Fedora
Posts: 38

Original Poster
Rep: Reputation: Disabled
Thank you for the answer, it helped.
 
Old 10-07-2014, 07:32 PM   #4
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,670
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
Furthermore, many companies set up their own internal CA's, run by their central security services and sometimes set up as a tier of CA's, and they then program browsers and so-forth to accept only that signature authority when accessing internal sites and resources.

They sometimes go one step further than that, and use individually-issued certificates (similarly "self-"signed) to identify the computers that are accessing restricted services. You can go a very long way with existing public-key crypto technology if you use it well.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Shrink partition (LVM encrypted PVs + encrypted LVs) gedaj Linux - Newbie 2 05-22-2013 03:44 AM
Resizable encrypted LVM requiring just one password on boot (encrypted volume group)? Nyyr Linux - Software 9 01-24-2013 05:52 AM
sudo: Can't contact LDAP server with SSL and PAM sebastienliu Linux - Server 1 01-15-2013 12:02 AM
Draw xgraph for the inter-contact time & contact time dinelka Linux - Software 1 07-08-2012 12:21 PM
How to import/use CAcert SSL root certificate to use SSL with Xchat IRC client? GrapefruiTgirl Linux - Software 9 04-05-2011 09:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration