security - Safety of Self-signed certificate in a point-to-point socket with SSL -
i confirm understood using self-signed certificates if used point-to-point socket ssl.
suppose have 1 client , 1 server. generate self-signed certificate , install certificate on both server , client. machines otherwise accept no other certificates.
does mean in order mitm attacks, attacker must physically hack 1 of machines obtain certificate?
what other vulnerabilities setup present if these 2 machines using certificate?
thanks!
yes, correct. in scenario describe, certificate used convenient way move public key machine.
if configure client , server trust certificate, communication secure long can keep private key safe.
other attack vectors exploiting other vulnerabilities in application or operating system runs in.
Comments
Post a Comment