Full Disclosure mailing list archives

Re: SSL VPNs and security


From: "Brian Eaton" <eaton.lists () gmail com>
Date: Fri, 9 Jun 2006 15:08:47 -0400

On 6/9/06, Tim <tim-security () sentinelchicken org> wrote:
For non-managed systems (which you
shouldn't allow into your network via a VPN anyway), installing a CA
cert is as simple as clicking on a link ONCE, and installing the cert.
This cert can be distributed over a VeriSign secured SSL connection.

Are you referring to telling end-users to click "Accept this
certificate permanently" box on the certificate warning pop-up?  Or is
there a software package out there that can do this without the
warning pop-up?

- Brian

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: