Re: [Bacula-users] Feature request: more flexible TLS cert validation

2007-03-11 Thread Pierre Bernhardt
Kern Sibbald schrieb: > Hello, Hi, > > Unless I am mistaken, even if there is a duplicate CN as you fear, it seems > to > me it should pose no problems because the certificate would not match. > > Does someone more experienced with TLS know the answer to that? Hmm. I'm not an expert but I've le

Re: [Bacula-users] Feature request: more flexible TLS cert validation

2007-03-08 Thread Kern Sibbald
Hello, Unless I am mistaken, even if there is a duplicate CN as you fear, it seems to me it should pose no problems because the certificate would not match. Does someone more experienced with TLS know the answer to that? Best regards, Kern On Thursday 08 March 2007 15:00, Jorj Bauer wrote: >

[Bacula-users] Feature request: more flexible TLS cert validation

2007-03-08 Thread Jorj Bauer
What: The ability for the director to validate a Client (FD) CN against an arbitrary set of patterns (cf. TLS Allowed CN options for clients), rather than the hostname. Why: DNS is not secure. Also, computers may move to new networks, and local policy may tie hostnames to a