RE: enforcing mutual auth from the client

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> It is not clear what threat model warrants taking special action when the client
> certificate is not requested.  It could equally be requested and then largely
> ignored.

A client in a highly secured network knows that every server it connects to will require a client certificate.  If the request fails to arrive, it's either a misconfiguration or a compromised server.  In either case, the client prefers to fail and make the user aware of a problem rather than risk compromising sensitive data with the user unaware that there was unexpected behavior.




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux