BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Delivering mail to folders
- Subject: [Discuss] Delivering mail to folders
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- Date: Tue, 2 Feb 2016 12:57:46 +0000
- In-reply-to: <BY2PR04MB1842E3E9926DC4CC416BDFABDCDF0@BY2PR04MB1842.namprd04.prod.outlook.com>
- References: <56AE7E30.8000002@thekramers.net> <BY2PR04MB18423BE3482CCEA9254F8560DCDD0@BY2PR04MB1842.namprd04.prod.outlook.com> <56AE96AD.2090105@thekramers.net> <BY2PR04MB184227277919A01002E80C12DCDE0@BY2PR04MB1842.namprd04.prod.outlook.com> <56AFA61E.6000103@gmail.com> <BY2PR04MB1842E972934371DD6D763C24DCDE0@BY2PR04MB1842.namprd04.prod.outlook.com> <CA+h9Qs754TkOD7Kj_xa0d2FQ+7epjHpR7R2ZWt5iuC6za7wPXg@mail.gmail.com> <BY2PR04MB1842E3E9926DC4CC416BDFABDCDF0@BY2PR04MB1842.namprd04.prod.outlook.com>
The important characteristic is whether or not the CA root private key is ever exposed to any servers or clients. For example, if you used a self-signed cert (no separate CA) on a server, that server requires the CA root private key in order to serve webpages, and if you installed that cert into the CA root trust store of your clients, then if the server gets compromised, the attacker can impersonate literally any domain on any server, completely undermining your entire SSL/TLS infrastructure, with the ability to MITM attack every connection. If you generate a CA, keep its private key private, and use it to sign a separate server cert, then if the server gets compromised, the worst the attacker can do is malicious things with the compromised server.
- References:
- [Discuss] Delivering mail to folders
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Delivering mail to folders
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] Delivering mail to folders
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Delivering mail to folders
- From: jabr at blu.org (John Abreau)
- [Discuss] Delivering mail to folders
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Delivering mail to folders
- Prev by Date: [Discuss] Delivering mail to folders
- Next by Date: [Discuss] Duplicate entries in Gnu PG
- Previous by thread: [Discuss] Delivering mail to folders
- Next by thread: [Discuss] Delivering mail to folders
- Index(es):