Re: Issue 650, SSL certificate authority validation questions
From: <mass_at_akuma.org>
Date: 2003-01-25 02:21:03 CET
Justin Erenkrantz wrote:
--On Friday, January 24, 2003 16:58:01 -0700 David Waite
I assume all of these should be in the servers file. Other than names
I think the CA options you have listed would be system wide rather
I assume that they will be put into the servers 'default' section, which
- should ssl-authorities-file have a default if not specified? If so,
Yes, I think so. ~/.subversion/certs/ sounds like a reasonable
Perhaps you could do some registry entries on Win32, but I've seen
I think I will just defer having a default for the time being, then.
- should ignore-ssl-host-mismatch allow you to specify an alternate
I don't think so. An 'alternate-ssl-host-name' per-server option
noted.
- should there be prompting on the above errors?
My hunch is no, but it should print out a warning at the very least.
From a security standpoint, they should all be 'fatal' and require
Eventually it might be nice to have the OpenSSH client behavior of
I would also probably suggest that you do this on a branch rather than
I would need access to a branch to do that, but other than that its fine
-David Waite
---------------------------------------------------------------------
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.