Re: To SSL-client-auth or not to SSL-client-auth, that is the question(?)

2006-06-30 Thread Duane
Anders Rundgren wrote: Security-wise there are no differences, assuming appropriate methods are used. Well there is a form drop down to create client certs, why can't there be something similar for choosing client certs to auth inside the form (and some kind of hint method to tell if there i

To SSL-client-auth or not to SSL-client-auth, that is the question(?)

2006-06-30 Thread Anders Rundgren
Hi, In theory SSL-client-authentication ought to be the only way to authenticate to web-servers using PKI. I reality this is not the case in many large-scale PKIs. In addition, things have been complicated by the introduction of Microsoft's CardSpace (formerly InfoCards) system, which use