|
|
Log in / Subscribe / Register

Using certificates for SSH authentication

Using certificates for SSH authentication

Posted Nov 9, 2022 5:43 UTC (Wed) by buck (subscriber, #55985)
In reply to: Using certificates for SSH authentication by mss
Parent article: Using certificates for SSH authentication

> I guess you mean BER here, since that's how X.509 certificates are usually encoded.

Wouldn't it be DER, so there's no choice of whether to use indefinite-length encoding and other such things that lead to a multitude of possibilities for finding hash collisions? Or maybe it's just whatever the PKCS or IETF specs say, more to the point.

At any rate, trusting the X.509 public CA ecosystem, while convenient, has its downsides. This recent article (paywalled, after free monthly article limit exceeded, i believe) offers a particularly compelling case study:

Mysterious company with government ties plays key internet role

https://www.washingtonpost.com/technology/2022/11/08/trus...


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds