4 ms·
'azet noted in another forum that with pathlen:0, this cert cannot be used to issue other intermediate certs, such as they would to place in a traffic inspectio
by mikecb 10y ago
'azet noted in another forum that with pathlen:0, this cert cannot be used to issue other intermediate certs, such as they would to place in a traffic inspection device.
- kerkeslager 10y agoBlue Coat can trivially work around this limitation by placing the intermediate cert on a server. Now when the traffic inspection device wants a (leaf) cert, it calls home to the server and the server provides it.
- mikecb 10y agoSeems like it would have unacceptable performance limitations.
- kerkeslager 10y agoThat's your source of security? Performance limitations? I'm not even convinced it would have performance limitations. Let's say Alice and Bob are communicating and Eve has the BlueCoat device in the middle. Alice sends the initial connection request to Bob, but Eve gets it instead. Eve then sends a new initial request to Bob AND a request to the BlueCoat server to get the fake cert in parallel. As long as the BlueCoat server responds with similar latency to Bob, Alice won't see any significant difference in latency as compared to Eve simply forwarding the requests.
- mikecb 10y agoI didn't say that at all.
- kerkeslager 10y agoOkay, so what did you mean when you said, "Seems like it would have unacceptable performance limitations."
- tremon 10y agoDo browsers actually verify and enforce the pathlen property of a CA?