Re: Subject: IMPORTANT: Mandatory password and ssh key change by 2011-11-30

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, Oct 12, 2011 at 08:19:27PM +0200, Henrik Nordström wrote:
> 
> And why is so much of the Fedora inftrastructure relying on plain text
> password exchanges (within SSL, but still plain text at the Fedora
> servers) when there is both HTTP digest authentication (no plaintext
> seen by Fedora servers) and SSL certificates and SSH keys which all
> three serves a much better identification method?
> 
Don't know about hte others but we've actually looked at SSL certificates
several times.  Unfortunately, they have the client side tooling around SSL
certificates makes them less attractive than they could be.  It seems that
what we need is the equivalent to an ssh-agent for SSL certificates to bring
that end of things up to par.

-Toshio

Attachment: pgpTCxdrK2XXJ.pgp
Description: PGP signature

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux