security - Safety of Self-signed certificate in a point-to-point socket with SSL -


i confirm understood using self-signed certificates if used point-to-point socket ssl.

suppose have 1 client , 1 server. generate self-signed certificate , install certificate on both server , client. machines otherwise accept no other certificates.

does mean in order mitm attacks, attacker must physically hack 1 of machines obtain certificate?

what other vulnerabilities setup present if these 2 machines using certificate?

thanks!

yes, correct. in scenario describe, certificate used convenient way move public key machine.

if configure client , server trust certificate, communication secure long can keep private key safe.

other attack vectors exploiting other vulnerabilities in application or operating system runs in.


Comments

Popular posts from this blog

c# - MSAA finds controls UI Automation doesn't -

python - mat is not a numerical tuple : openCV error -

wordpress - .htaccess: RewriteRule: bad flag delimiters -