FDS & Red Hat Certificate System

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



>
> ...the management is a little concerned about MITM attacks against the FDS, so we need a way to
> verify that the server saying that it's our FDS really is the FDS.  Right now no certs are
> deployed on the clients, we're using them only for SSL traffic encryption.

If I'm interpreting your question right, I think you're already covered 
for this as long as:
- Your client apps do server cert verification.
- Your internal CA isn't compromised.
- Your cert/key DB files on your FDS servers haven't been compromised.

You shouldn't need to sign a new certificate for every client, you just 
need a copy of the CA certificate on each client.




Susan wrote:
> Hi, everyone.  I think this subject has been briefly raised before but I've more questions.
>
> Can RHCS be used to hand out CA certs to Unix clients (linux/solaris)?  
> Has anybody done this?
> RHCS doesn't seem to be opensourced.  Is there a reliable free alternative?
>
> The problem I'm trying to solve is that my CA cert is self-signed.  I guess even if it weren't,
> the management is a little concerned about MITM attacks against the FDS, so we need a way to
> verify that the server saying that it's our FDS really is the FDS.  Right now no certs are
> deployed on the clients, we're using them only for SSL traffic encryption. 
>
> What's the best way to go about doing this?  I don't want to manually create/deploy dozens of
> certs for various clients.  I also need a way to implement CRL somehow, in case a box is
> comprosmised.
>
> Thank you.
>
> __________________________________________________
> Do You Yahoo!?
> Tired of spam?  Yahoo! Mail has the best spam protection around 
> http://mail.yahoo.com 
>
> --
> Fedora-directory-users mailing list
> Fedora-directory-users at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-directory-users
>
>   





[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux