From owner-freebsd-questions@FreeBSD.ORG Tue Jan 6 09:22:43 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A8A8A106566C for ; Tue, 6 Jan 2009 09:22:43 +0000 (UTC) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Received: from wojtek.tensor.gdynia.pl (wojtek.tensor.gdynia.pl [IPv6:2001:4070:101:2::1]) by mx1.freebsd.org (Postfix) with ESMTP id B9AB78FC13 for ; Tue, 6 Jan 2009 09:22:39 +0000 (UTC) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Received: from wojtek.tensor.gdynia.pl (localhost [IPv6:::1]) by wojtek.tensor.gdynia.pl (8.14.3/8.14.3) with ESMTP id n069MUHT034155; Tue, 6 Jan 2009 10:22:30 +0100 (CET) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Received: from localhost (wojtek@localhost) by wojtek.tensor.gdynia.pl (8.14.3/8.14.3/Submit) with ESMTP id n069MT53034152; Tue, 6 Jan 2009 10:22:30 +0100 (CET) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Date: Tue, 6 Jan 2009 10:22:29 +0100 (CET) From: Wojciech Puchar To: Mel In-Reply-To: <200901052258.39785.fbsd.questions@rachie.is-a-geek.net> Message-ID: <20090106102124.O34151@wojtek.tensor.gdynia.pl> References: <20090102164412.GA1258@phenom.cordula.ws> <20090103013825.18910bf5@gumby.homeunix.com> <495F5DD7.2070302@infracaninophile.co.uk> <200901052258.39785.fbsd.questions@rachie.is-a-geek.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Cc: freebsd-questions@freebsd.org Subject: Re: Foiling MITM attacks on source and ports trees X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Jan 2009 09:22:44 -0000 >> someone like the FreeBSD Foundation as an appropriate body to own the cert. > > > I would actually trust a self-signed cert by the FreeBSD security officer, > more then one by Verisign. of course. there is no need to have an "authority" to make key pairs, everybody do it alone. actually i would fear using such keys because i'm sure such companies do have a copy of both keys.