[Cryptography] client certificates ... as opposed to password hashing

Tony Arcieri bascule at gmail.com
Wed May 28 17:48:00 EDT 2014


On Wed, May 28, 2014 at 2:20 PM, Jerry Leichter <leichter at lrw.com> wrote:

> *Using* client certificates, once they've been set up problem, is a
> reasonably well solved problem in a number of existing implementations.
>  What's not solved in any I know of - and others here have made the same
> comment about all the implementations *they* know of, which probably pretty
> much covers the space - is getting and configuring a client certificate,
> and beyond that knowing *what* you should get, for what purposes, and what
> you actually gain by having such a thing (in terms that make sense in the
> end-user's world).
>

As I've already mentioned, this can be done using the HTML5 <keygen> tag:

https://developer.mozilla.org/en-US/docs/Web/HTML/Element/keygen

-- 
Tony Arcieri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20140528/a0fcba59/attachment.html>


More information about the cryptography mailing list