3 ms·
I'm curious to know what you'd recommend for people who are looking to build applications around novel network protocols that aren't interested in the the certi
by ary 12y ago
I'm curious to know what you'd recommend for people who are looking to build applications around novel network protocols that aren't interested in the the certificate authority aspect of TLS?
- bjornsing 12y agoThere's an RFC on TLS with raw public keys that you should probably check out: http://tools.ietf.org/html/draft-ietf-tls-oob-pubkey-02 http://tools.ietf.org/html/draft-ietf-tls-oob-pubkey-02.
- tptacek 12y agoThere's no reason you have to use CAs to authenticate TLS. Plenty of enterprise tools keep whitelists of certificate hashes instead.
- jewel 12y agoThere are several TLS modes that don't use certificates. SRP and PSK are the two that I have some limited experience with. Both require sharing a password or key beforehand through some other medium. If you're not concerned with man-in-the-middle attacks, then you could also use the ANON modes.
- higherpurpose 12y agoThis maybe: https://github.com/okTurtles/dnschain https://github.com/okTurtles/dnschain
- revelation 12y agoIf you control the client software, theres no reason to use a certificate authority instead of making your own CA or just using self-signed certificates.