TimC
2011-08-26 03:43:35 UTC
When I go to a self-signed https page or a page signed by a
certificate with a different hostname to that browsed (eg, when I go
to my domain and get the certificate for the webserver within that is
hosted on that domain name, ie hostname.domain.org != domain.org; yes
I could change it, but then it'd still ask me about the self-signed
cert), opera asks me whether I want to accept the certificate. I go
to the security page, select "remember my choice for this
certificate", and click "approve". What I would expect is that next
time I browse to that site, regardless of whether I have restarted
opera, it remembers that I approved that certificate.
Very much like ssh keys. I'm willing to accept that 1 time risk that
there was a man in the middle that stole my credentials when I first
logged in. I logged in soon after I provisioned an internal service
so I expect the risk is lower then, that once, than usual. But I'm
not willing to accept the risk every single time I log in. I want to
be alerted when, and only when, the ssl certificate has changed. It
hasn't, yet opera keeps prompting me (possibly after a browser restart
- I haven't checked, but I frequently get bugged by it).
What am I doing wrong?
certificate with a different hostname to that browsed (eg, when I go
to my domain and get the certificate for the webserver within that is
hosted on that domain name, ie hostname.domain.org != domain.org; yes
I could change it, but then it'd still ask me about the self-signed
cert), opera asks me whether I want to accept the certificate. I go
to the security page, select "remember my choice for this
certificate", and click "approve". What I would expect is that next
time I browse to that site, regardless of whether I have restarted
opera, it remembers that I approved that certificate.
Very much like ssh keys. I'm willing to accept that 1 time risk that
there was a man in the middle that stole my credentials when I first
logged in. I logged in soon after I provisioned an internal service
so I expect the risk is lower then, that once, than usual. But I'm
not willing to accept the risk every single time I log in. I want to
be alerted when, and only when, the ssl certificate has changed. It
hasn't, yet opera keeps prompting me (possibly after a browser restart
- I haven't checked, but I frequently get bugged by it).
What am I doing wrong?
--
TimC
Love makes the world go 'round, with a little help from intrinsic
angular momentum. --unknown
TimC
Love makes the world go 'round, with a little help from intrinsic
angular momentum. --unknown