Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe because of the PKI features of SSL?

For instance...with an SSH client, the first time you contact a new server you're asked to verify the remote host's identity. I bet most of us just blindly type 'y' at this point despite the security implications. On the other hand, with SSL, you can have the server cert signed by a CA the client trusts.



OpenSSH supports PKI-based authentication and server certificate signing as of 5.4. Very useful in big enterprises and higher-security environment.

http://blog.habets.pp.se/2011/07/OpenSSH-certificates


Very cool, thanks for the info.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: