LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-18-2013, 11:13 PM   #16
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941

What I was saying about some big-client corporate networks (those who have lots of "road warriors," or very sensitive information), is that they create a certificate-authority (CA) within their corporation, and arrange for all of their computers to accept that authority (by adding it to the list on every browser).

Then, they protect sensitive internal sites and info by arranging those resources to accept only SSL connections, which may only be secured by a certificate issued by the company-CA ... not any external entity such as VeriSign.

The rationale is simple: "we trust ourselves, and no one else, with regard to this, our bread-and-butter data." Which is of course a very valid point-of-view.

The "chain of trust" notion of SSL, while it looks just-fine on paper, is really quite weak: VeriSign (and all the rest) really don't have much ability to verify the credentials that someone may present when they show-up wanting to buy a certificate. They naturally tend to just take the money, after maybe-performing a slight bit of "due diligence." Hardly unheard-of ... yet, not good enough.
 
Old 09-22-2013, 12:44 AM   #17
abdo_elrahman
LQ Newbie
 
Registered: Mar 2007
Location: Hong Kong
Distribution: Fedora , RHEL , Ubunto , Centoos,
Posts: 13

Original Poster
Rep: Reputation: 0
Hey folks,
Any recommended CA to get a one for my website, looks like some folks here have experience in that?
 
Old 09-22-2013, 04:48 AM   #18
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Removing ssl security but sticking to https://

Comodo
Verisign
GoDaddy

Whoever you registered your domain (if you have one) would most likely also sell SSL certs.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to enable https/ssl in wine Barx General 0 08-18-2010 12:44 PM
LXer: Boost Your Geronimo Security with SSL and HTTPS LXer Syndicated Linux News 0 09-01-2006 07:54 PM
https server..cetificate and ssl name_in_use450 Linux - General 0 09-05-2004 11:03 AM
Apache2, SSL, HTTPS... KneeLess Debian 3 09-02-2004 09:44 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration