看板FB_security
標 題Re: RFC: Proposal: Install a /etc/ssl/cert.pem by default?
發信站NCTU CS FreeBSD Server (Thu Jul 3 22:16:25 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
There is always going to be skepticism about who to trust by default. The CA system is out of control and it worries me as well. However, if we do not make an effort to provide a default trust store why do we enforce verification by default? I feel it would be more consistent to disable verification requiring those who know what they're doing to create their own trust store and pass --verify-peer to fetch manually. I'm on the verge of breaking my keyboard every time I jump onto a random FreeBSD server and try to fetch something over https.
--no-verify-peer is now muscle memory; that isn't a good sign. I eagerly await verification through DNSSEC to take off.
-2c
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"