LWN.net Logo

Please make OpenSSL clients reject insecure certificates

Please make OpenSSL clients reject insecure certificates

Posted May 16, 2008 14:07 UTC (Fri) by scarabaeus (subscriber, #7142)
Parent article: Debian, OpenSSL, and a lack of cooperation

Unfortunately, fixing this bug does not fix the problems it has caused: Many many insecure
certificates have been created out there. From a security POV, it would be appropriate if
newer upstream OpenSSL versions refused to connect to public servers whose certificates can be
attacked by a man in the middle. Otherwise, there is a false sense of security, which is worse
than no security at all. But I don't think there are plans to implement anything like that,
are there??


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds