security - Safety of Self-signed certificate in a point-to-point socket with SSL -


i confirm understood using self-signed certificates if used point-to-point socket ssl.

suppose have 1 client , 1 server. generate self-signed certificate , install certificate on both server , client. machines otherwise accept no other certificates.

does mean in order mitm attacks, attacker must physically hack 1 of machines obtain certificate?

what other vulnerabilities setup present if these 2 machines using certificate?

thanks!

yes, correct. in scenario describe, certificate used convenient way move public key machine.

if configure client , server trust certificate, communication secure long can keep private key safe.

other attack vectors exploiting other vulnerabilities in application or operating system runs in.


Comments

Popular posts from this blog

python - mat is not a numerical tuple : openCV error -

c# - MSAA finds controls UI Automation doesn't -

wordpress - .htaccess: RewriteRule: bad flag delimiters -