4 ms·
In general, you'd be right; in parent's hypothetical scheme, the trust model is different because your systems exist on both sides of the exchange (in normal We
by mrbabbage 12y ago
In general, you'd be right; in parent's hypothetical scheme, the trust model is different because your systems exist on both sides of the exchange (in normal Web communication, this obviously isn't the case). You simply configure your clients to only trust this single certificate that you yourself created and installed on your server. No one could MITM you unless they recreated an identical certificate from scratch, which is mathematically challenging.