Discussion:
Why doesn't opera remember SSL certificates when asked?
(too old to reply)
TimC
2011-08-26 03:43:35 UTC
Permalink
When I go to a self-signed https page or a page signed by a
certificate with a different hostname to that browsed (eg, when I go
to my domain and get the certificate for the webserver within that is
hosted on that domain name, ie hostname.domain.org != domain.org; yes
I could change it, but then it'd still ask me about the self-signed
cert), opera asks me whether I want to accept the certificate. I go
to the security page, select "remember my choice for this
certificate", and click "approve". What I would expect is that next
time I browse to that site, regardless of whether I have restarted
opera, it remembers that I approved that certificate.

Very much like ssh keys. I'm willing to accept that 1 time risk that
there was a man in the middle that stole my credentials when I first
logged in. I logged in soon after I provisioned an internal service
so I expect the risk is lower then, that once, than usual. But I'm
not willing to accept the risk every single time I log in. I want to
be alerted when, and only when, the ssl certificate has changed. It
hasn't, yet opera keeps prompting me (possibly after a browser restart
- I haven't checked, but I frequently get bugged by it).

What am I doing wrong?
--
TimC
Love makes the world go 'round, with a little help from intrinsic
angular momentum. --unknown
Jorgen Grahn
2011-08-26 18:31:52 UTC
Permalink
On Fri, 2011-08-26, TimC wrote:
...
Post by TimC
Very much like ssh keys. I'm willing to accept that 1 time risk that
there was a man in the middle that stole my credentials when I first
logged in. I logged in soon after I provisioned an internal service
so I expect the risk is lower then, that once, than usual. But I'm
not willing to accept the risk every single time I log in. I want to
be alerted when, and only when, the ssl certificate has changed.
I don't know if I've ever been in Tim's situation, but I'd like to add
a +1 to that. The ssh host key metaphor is spot on.

/Jorgen
--
// Jorgen Grahn <grahn@ Oo o. . .
\X/ snipabacken.se> O o .
Loading...