> And the NTS-KE and NTPD are NOT on the same host?

No.  I misinterpreted your question.


>> I don't understand that use case.  Without checking the certificate,
>> you have no real security.
> Not complete security, but at least encryption.  And there are levels of
> validation.  If you are off net, you can't completely validate the cert, but
> you can partially validate it.  Maybe you would want to pin it.

What does partial validation mean?  What does "pin it"? mean


-- 
These are my opinions.  I hate spam.



_______________________________________________
devel mailing list
devel@ntpsec.org
http://lists.ntpsec.org/mailman/listinfo/devel

Reply via email to