Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: PGP vs. certificate from Verisign
From: Ben Laurie <ben () algroup co uk>
Date: Sat, 10 May 2003 21:03:40 +0100

Steve Poirot wrote:
I'm 98% sure that the key pair is generated on the client machine and
that just the public key is transmitted to the CA.  The reason I say 98%
instead of 100% is that it's possible that a CA just makes it look like
that's what's happening.  This could be verified by sniffing the session. 

Well, the amusing thing is you can do it either way. As it happens
neither Thawte nor Verisign (yeah, OK, they're the same thing) have sold
out enough to generate private keys.

I still hear people telling me occasionally that there are sound reasons
for having the CA generate the private key. Strangely they never quite
get round to specifying what those reasons are.

Cheers,

Ben.

-- 
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]