看板FB_security
標 題Re: RFC: Proposal: Install a /etc/ssl/cert.pem by default?
發信站NCTU CS FreeBSD Server (Thu Jul 3 12:28:34 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On 07/03/14 03:47, Eitan Adler:
> IMHO, it is sane to follow the same policy that Mozilla follows and to
> use their root store by default.
It's policy define very generic requirements only. Almost anyone can apply.
But I'm not going to discuss Mozila's policy here beyond my opinion that
it's definition of "trusted" is near to meaningless.
>> If I consider a CA to be trustworthy, I will insert it's certificate to
>> trusted store. No one is welcomed to make such decision in behalf of me.
>
> So remove or edit the defaults.
Be sure I'm doing it already with browsers stores. But I wish
system/program shall be safe by default because not all users are
experts that can recognize dangerous defaults.
Are you ready to recommend a CA as trustworthy and take responsibility
for such advice ?
OK, I expressed my personal opinion in full and I'm not wishing to start
a flame war here ;-)
Cheers
Dan
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"