BLU Discuss list archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] [BLU/Officers] update instructions for key signing

Bill Ricker <bill.n1vux at> writes:

>  (b) closed intranet (no BYOD allowed) where one IT org controls both the
> desktops and the webservers, and you install the Corp private selfsigned CA
> key into IT release of IE/Edge, FF, Chrome.

The downside of this latter approach is that the IT org can then sign
certs for *ANY* other site and therefore intercept all HTTPS traffic
they wish to see.


       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL:    PP-ASEL-IA     N1NWH
       warlord at MIT.EDU                        PGP key available