[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip / qa] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Edit][Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
4chan
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


Toggle

Starting February 1st, 4chan Passes are increasing in price.

One year: $30, Three years: $60


[Advertise on 4chan]


File: Screenshot_1.png (24 KB, 410x470)
24 KB
24 KB PNG
How are DigiCert and GlobalSign still around with their paid SSL certificates with shady slogans like """brand protection""" and """Domain reputation monitoring""" when anyone can generate a self-signed SSL certificate in OpenSSL that will encrypt their https traffic the exact same way?
>>
>>103928545 (OP)
Because nobody trust selfsigned you tard. Get a job.
>>
>>103928564
Why would someone trust a certificate signed by some company out there instead of one signed directly by the site owner?
>>
>>103928682
I don't have the root certificate of every random website owner and him delivering it to me right before the website over the same medium is unsecure as hell, anyone MITMing the connection could just give their own root certificate and chain of trust instead after that.
>>
>>103928692
How is it 2025 and still no algorithm for validating https keys like in SSH?
>>
>>103928738
>like in ssh
...you mean manually? or what magical key management system have you come up with for SSH?
>>
>>103928545 (OP)
>>103928682
Why would you sign your certificates yourself when Let’s encrypt does it for free?
>>
>>103928545 (OP)
Let's Encrypt exists
Just let the other firms die
>>
>>103928682
You still need a way of knowing that it's the actual site's owner who signed the cert. I can create my own self-signed SSL cert right now for any domain, and provided I managed to get access to that domain? How would you tell my self-signed cert apart from the real site-owners' without some 3rd party involvement?

Not saying that you can't figure out some convoluted way of doing it, but the system of having a known 3rd-party handle this for you is far simpler and easier to implement.
>>
Look up how the x509 system works.
That said, Letsencrypt is an absolute champion and I have had many certs signed by them and they're all fully trusted.

I've also signed my own certs for my internal network, but it involves distributing a CA to all my devices.
>>
>>103928738
There actually is, you just tell the browser that you do, infact, trust the sites' certificate despite it warning you about it. Which is exactly the same as when you SSH to a host machine for the first time and your client doesn't have a record of the public key and warning you about this.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip / qa] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Edit][Settings] [Search] [Mobile] [Home]
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.