help-gnutls
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: "known in advance" public key authentication?


From: Ivan Shmakov
Subject: Re: "known in advance" public key authentication?
Date: Wed, 07 Nov 2012 22:49:48 +0700
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/23.2 (gnu/linux)

>>>>> Graham Murray <address@hidden> writes:
>>>>> On Wed, 2012-11-07 at 14:33 +0000, Ivan Shmakov wrote:

[…]

 >> A feature of this application is that the public keys of the peers
 >> are effectively “known in advance”, so, while self-signed
 >> (unsigned?) X.509 certificates (or some OpenPGP ones) could be
 >> employed, there's no practical benefit from CC/WoT verification.

 >> Hence, the question is: is there a way to specify the local key pair
 >> and the remote public key to GnuTLS “directly”, just prior to
 >> connecting the remote?

 > Would PSK not do what you want?

        Unfortunately, no.  The keys are known in advance precisely
        because they're public.

-- 
FSF associate member #7257




reply via email to

[Prev in Thread] Current Thread [Next in Thread]