BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Delivering mail to folders
- Subject: [Discuss] Delivering mail to folders
- From: tmetro+blu at gmail.com (Tom Metro)
- Date: Mon, 01 Feb 2016 13:38:22 -0500
- In-reply-to: <BY2PR04MB184227277919A01002E80C12DCDE0@BY2PR04MB1842.namprd04.prod.outlook.com>
- References: <56AE7E30.8000002@thekramers.net> <BY2PR04MB18423BE3482CCEA9254F8560DCDD0@BY2PR04MB1842.namprd04.prod.outlook.com> <56AE96AD.2090105@thekramers.net> <BY2PR04MB184227277919A01002E80C12DCDE0@BY2PR04MB1842.namprd04.prod.outlook.com>
Edward Ned Harvey (blu) wrote: >David Kramer wrote: >> ...would it be reasonable and possible to use a self-signed cert for starters... > > Ever-so-slightly better than no encryption. Huh? We're talking about using a self-signed cert for IMAP access, right? Self-signed certs have all the same cryptographic benefits as a CA signed cert, including having your client validate the cert, if you install your own root cert on your clients. The only down-side to self-signed certs is the inconvenience of having to install the root certs on your clients. This is why they aren't used for public web sites. Even without installing a root cert, many clients will warn you about the invalid cert, and if you agree to connect anyway, they give an option to let you store the exception. If implemented correctly, the client will warn again if the cert fingerprint changes, raising the bar (but not preventing) a MITM attack. -Tom -- Tom Metro The Perl Shop, Newton, MA, USA "Predictable On-demand Perl Consulting." http://www.theperlshop.com/
- Follow-Ups:
- [Discuss] Delivering mail to folders
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Delivering mail to folders
- References:
- [Discuss] Delivering mail to folders
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Delivering mail to folders
- Prev by Date: [Discuss] Delivering mail to folders
- Next by Date: [Discuss] Delivering mail to folders
- Previous by thread: [Discuss] Delivering mail to folders
- Next by thread: [Discuss] Delivering mail to folders
- Index(es):