RE: SSL and snail mail

2006-04-25 Thread David Schwartz
> We are splitting the SSL connection over our network and thus break > this thing. :( > > thanks and regards > -Krishna Split SSL is not SSL. SSL makes numerous things visible to the two endpoints and they are supposed to match. By splitting the SSL connection, you make these things not

Re: SSL and snail mail

2006-04-25 Thread Egon Andersen
Krishna M Singh wrote: We are splitting the SSL connection over our network and thus break this thing. :( thanks and regards -Krishna I simply have to ask, why the h... are you splitting the SSL connection? And checking of fingerprints are used in many other situations too. Say if you con

Re: SSL and snail mail

2006-04-25 Thread Victor Duchovni
On Wed, Apr 26, 2006 at 12:07:45AM +0530, Krishna M Singh wrote: > Some banks in Europe send the fingerprint of their certificate (i > guess this is MD5 or SHA digest hash of the certificate) over the > snail mail to their customer and customers are requested to match the > bank's secure server ce