[Devel] Re: [Users] TLS setup

Juha Heinanen jh at tutpro.com
Tue Oct 11 09:47:11 CEST 2005


Klaus Darilion writes:

 > The second problem: RFC3263 also states that by validating the domain in 
 > the certificate it is possible to detect hacked nameserver entries. But 
 > with your suggestion (using only a host certificate), this wouldn't be 
 > possible.

name server entries should be protected by dns means, not later by
application means.

-- juha



More information about the Devel mailing list