3 ms·
it's most likely important to check the signatures of the key. But yeah, this is one aspect where I always look confused about the security theater. You need a
by hngiszmo 12y ago
it's most likely important to check the signatures of the key. But yeah, this is one aspect where I always look confused about the security theater. You need a closed chain of trust (which can include a trusted root CA). Else it's all worthless. Two servers are almost as easy to MITM-attack as one if you are the oppressive government that has back doors to the common pre-installed ssl certs.