Why it's there in the first place, then?
Why it's there in the first place, then?
Posted Jun 16, 2011 19:14 UTC (Thu) by iabervon (subscriber, #722)In reply to: Why it's there in the first place, then? by khim
Parent article: WebOS: the other Linux-based mobile platform
Actually, the sensible thing is to sync your self-signed certificate from your IT-imaged desktop. A very secure policy would be: the phone will not connect to an unrecognized IMAPS server, and won't let you ignore the issue or trust the certificate from the connection, but it will let you supply the root of trust that you expect the site to have and use that instead of the usual PKI root certificates. Sure, the vast majority of people won't be able to use this to authenticate their connections, but that's because they're using gmail. People who have some person relationship with their mail servers can get the correct root of trust in advance. (This also would mean that you'd generally have a configuration where you don't trust your employer in general, but you do trust your employer to authenticate your work email server.)
