(OT)

* Dave Thompson wrote on Thu, Sep 24, 2009 at 19:23 -0400:
> But 'ca' by default, and thus it appears to me CA.pl 
> always, also prompt for the CA key passphrase (unless 
> insecurely clear), and you're not complaining about that. 

I think it depends where it is stored if no passphrase is
insecure. I think it could be even more insecure to have an
"autosigner" that blindly signed any malicious incoming CSRs
without giving the security officer any chance to say NO... ;)

SCNR.

oki,

Steffen





























--[ end of message ]----------------------------------------------->8=======



 
About Ingenico: Ingenico is the world’s leading provider of payment solutions, 
with over 15 million terminals deployed across the globe. Delivering the very 
latest secure electronic payment technologies, transaction management and the 
widest range of value added services, Ingenico is shaping the future direction 
of the payment solutions market. Leveraging on its global presence and local 
expertise, Ingenico is reinforcing its leadership by taking banks and 
businesses beyond payment through offering comprehensive solutions, a true 
source of differentiation and new revenues streams.
 This message may contain confidential and/or privileged information. If you 
are not the addressee or authorized to receive this for the addressee, you must 
not use, copy, disclose or take any action based on this message or any 
information herein. If you have received this message in error, please advise 
the sender immediately by reply e-mail and delete this message. Thank you for 
your cooperation.
 P Please consider the environment before printing this e-mail
 
 
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to