On 2013-09-20 04:30, Javier wrote:
> But a bit contradictory to accept a certificate that has been issued by a CA
> you don't trust, just for the main purpose of establish an SSL connection.

It seems to be contradictory, but it is not.  You often cannot control
the certificate of your peer server.  In case its certificate is issued
by a large CA, you really want to make sure you're connecting to this
specific server, and not any other server with certificate issued by the
same CA.  Web browsers use CNAME/SubjectAltName verification to solve
the same problem in a different way.

Mike

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
stunnel-users mailing list
[email protected]
https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users

Reply via email to