It's not a joke, it's a fact. And in my opinion it's MUCH better to use a 
small encrypted partition so store a startupcript with passphrases then to 
just have the script lying around on the server. If you have a better 
solution I'd like to see it.
You will have to enter the console to enter the passphrase. You can't have 
automated security, then there is no security.
The thing is... If you run a commercial server and offer quality of service 
to you customers you need to have a secure system with protected 
passphrases. And I don't think they'll hang around for long if you have 
sudden uncontrolled reboots, do you? Only controlled, short time restarts.

Oh, and just so you know it; There is no such thing as a hack-proof server. 
If someone is determined to hack you, they WILL get in (unless you actually 
know exactly who it is and call the cops on them).


Best Regards

Are Hoel


At 12:56 29.11.2001 +0100, you wrote:
>Ha ha ha! Very ironic...... this is a joke, right?
>
>No? Oh dear... hardware key-files? This is like "dongles" that you used
>to have to plug into your parallel port to stop you installing software
>twice.
>
>You see the crazy situations you get into when you convince yourself you
>need a pass-phrase... The only way I can accpet pass-phrases is if you
>have a server which must be so secure that it must never, ever, be
>started without your knowledge and that the certificate must never, ever
>be used elsewhere. Then you keep the pass-phrase where no hacker can get
>it - in your head.
>
>The downside is that you have to go to the console of the machine and
>type it in every time you start apache so no automatic reboot or
>restart.

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to