<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenSUSE Linux: Creating Self-Signed SSL Certificates</title>
	<atom:link href="http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority/feed" rel="self" type="application/rss+xml" />
	<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority</link>
	<description>OpenSUSE Linux Tips, tricks, how-tos, opinions, and news</description>
	<lastBuildDate>Wed, 03 Mar 2010 15:54:37 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: OpenSUSE Linux: Creating Self-Signed SSL Certificates &#171; Mr.Novell&#8217;s Blog</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146172</link>
		<dc:creator>OpenSUSE Linux: Creating Self-Signed SSL Certificates &#171; Mr.Novell&#8217;s Blog</dc:creator>
		<pubDate>Thu, 18 Jun 2009 17:13:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146172</guid>
		<description>[...] Article By: SuseBlog [...]</description>
		<content:encoded><![CDATA[<p>[...] Article By: SuseBlog [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Morris</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146164</link>
		<dc:creator>Scott Morris</dc:creator>
		<pubDate>Fri, 12 Jun 2009 04:26:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146164</guid>
		<description>Vavai,
Glad it was helpful.  Thanks for stopping by!</description>
		<content:encoded><![CDATA[<p>Vavai,<br />
Glad it was helpful.  Thanks for stopping by!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Morris</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146163</link>
		<dc:creator>Scott Morris</dc:creator>
		<pubDate>Fri, 12 Jun 2009 04:25:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146163</guid>
		<description>Peter,
Thank you.  Glad you found it helpful.  And yeah, I did try to make it non-distro-specific where I could.  Thanks for stopping by.</description>
		<content:encoded><![CDATA[<p>Peter,<br />
Thank you.  Glad you found it helpful.  And yeah, I did try to make it non-distro-specific where I could.  Thanks for stopping by.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Collard</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146157</link>
		<dc:creator>Peter Collard</dc:creator>
		<pubDate>Wed, 10 Jun 2009 10:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146157</guid>
		<description>Have tried Yast, but as I hadn&#039;t a clue what I was trying to do, I wasn&#039;t very happy using it. Having been thru this process with its explanations I now feel a lot more confident knowing that I have something that will work on other distros as well as a suse system in single user mode for recovery. Next time I&#039;ll probably use Yast to save getting my notes out, but will at least understand what its trying to do. Thanks for the excellent posting.</description>
		<content:encoded><![CDATA[<p>Have tried Yast, but as I hadn&#8217;t a clue what I was trying to do, I wasn&#8217;t very happy using it. Having been thru this process with its explanations I now feel a lot more confident knowing that I have something that will work on other distros as well as a suse system in single user mode for recovery. Next time I&#8217;ll probably use Yast to save getting my notes out, but will at least understand what its trying to do. Thanks for the excellent posting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Morris</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146149</link>
		<dc:creator>Scott Morris</dc:creator>
		<pubDate>Mon, 01 Jun 2009 04:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146149</guid>
		<description>Absolutely not ideal for all situations, to be sure.  Especially for customers with credit card data, as you mentioned.  Absolutely great point.  However, when you need quick and dirty encryption between a satellite office and your intranet, it will work in a pinch. :)  Thanks for the message and thoughts.  Great points.  Thanks for stopping by.</description>
		<content:encoded><![CDATA[<p>Absolutely not ideal for all situations, to be sure.  Especially for customers with credit card data, as you mentioned.  Absolutely great point.  However, when you need quick and dirty encryption between a satellite office and your intranet, it will work in a pinch. <img src='http://www.suseblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   Thanks for the message and thoughts.  Great points.  Thanks for stopping by.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146148</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Sun, 31 May 2009 21:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146148</guid>
		<description>I never cease to be amazed that we build a GUI Interface for everything, and we want people to use it, and yet when we get down to teaching others, we use the console prompt.
Dont get me wrong, I love my console prompt for a lot of things but we do have a
CA Manager that is an optional install in Yast -
which takes you through managing all your self signed certificates and pars etc.

Why dont we teach people how to use the CA Manager in Yast.

One other thing that I thought I would mention is , if you use a self signed SSL Server/Client certificate, every user will be asked to &#039;TRUST and ACCEPT&#039; a certificate of &#039;unknown origin who&#039;s validity cannot be obtained&#039;...well something like that warning.

Not every one is going to trust your self signed SSL client part of the SSL Server Certificate - Some people will only accept a Server/Client certificate that is validated by a CA.

The other issue with self Signed SSL Server/Client Certificates is, once issued, I do not know of any mechanism to globally revoke them.

The advantage with a CA issued certificate is that you have the authority to instruct your CA to revoke the certificate should it start to be mischievously used.

Dont get me wrong, self signed SSL Server/Client certificates have their place, but personally I would have an issue when anyone asked me for me credit card number by an untrusted certificate that was not issued by a CA, mostly because anyone can create the pair, but more importantly the pair cannot be revoked.

Oh! I look forward to a lesson on how to use the CA Manager in Yast, particularly as we can then cover the hierarchical structure of certificates and their pairs with the graphic illustration and graphic tools.

I must say, all credit to you for tackling a hugely complex subject so very well and I look forward to a tutorial on S/MIME X.509 Email certificate creation and use.

Well Done!!!!!!</description>
		<content:encoded><![CDATA[<p>I never cease to be amazed that we build a GUI Interface for everything, and we want people to use it, and yet when we get down to teaching others, we use the console prompt.<br />
Dont get me wrong, I love my console prompt for a lot of things but we do have a<br />
CA Manager that is an optional install in Yast -<br />
which takes you through managing all your self signed certificates and pars etc.</p>
<p>Why dont we teach people how to use the CA Manager in Yast.</p>
<p>One other thing that I thought I would mention is , if you use a self signed SSL Server/Client certificate, every user will be asked to &#8216;TRUST and ACCEPT&#8217; a certificate of &#8216;unknown origin who&#8217;s validity cannot be obtained&#8217;&#8230;well something like that warning.</p>
<p>Not every one is going to trust your self signed SSL client part of the SSL Server Certificate &#8211; Some people will only accept a Server/Client certificate that is validated by a CA.</p>
<p>The other issue with self Signed SSL Server/Client Certificates is, once issued, I do not know of any mechanism to globally revoke them.</p>
<p>The advantage with a CA issued certificate is that you have the authority to instruct your CA to revoke the certificate should it start to be mischievously used.</p>
<p>Dont get me wrong, self signed SSL Server/Client certificates have their place, but personally I would have an issue when anyone asked me for me credit card number by an untrusted certificate that was not issued by a CA, mostly because anyone can create the pair, but more importantly the pair cannot be revoked.</p>
<p>Oh! I look forward to a lesson on how to use the CA Manager in Yast, particularly as we can then cover the hierarchical structure of certificates and their pairs with the graphic illustration and graphic tools.</p>
<p>I must say, all credit to you for tackling a hugely complex subject so very well and I look forward to a tutorial on S/MIME X.509 Email certificate creation and use.</p>
<p>Well Done!!!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vavai</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-146140</link>
		<dc:creator>Vavai</dc:creator>
		<pubDate>Fri, 22 May 2009 01:23:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-146140</guid>
		<description>Found it very useful while setting up openLDAP with TLS/SSL which need self-sign certificate.

Thank you.</description>
		<content:encoded><![CDATA[<p>Found it very useful while setting up openLDAP with TLS/SSL which need self-sign certificate.</p>
<p>Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Morris</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-131372</link>
		<dc:creator>Scott Morris</dc:creator>
		<pubDate>Wed, 10 Sep 2008 17:23:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-131372</guid>
		<description>dude,
Thank you, glad I could help your teacher.  Have a good one and thanks for stopping by.</description>
		<content:encoded><![CDATA[<p>dude,<br />
Thank you, glad I could help your teacher.  Have a good one and thanks for stopping by.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dude</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-131319</link>
		<dc:creator>dude</dc:creator>
		<pubDate>Wed, 10 Sep 2008 09:48:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-131319</guid>
		<description>Nice Tutorial mate,

Saved my TAFE teacher an entire lessons prep!!

no but seriously, easy to follow and very quick to set up :)</description>
		<content:encoded><![CDATA[<p>Nice Tutorial mate,</p>
<p>Saved my TAFE teacher an entire lessons prep!!</p>
<p>no but seriously, easy to follow and very quick to set up <img src='http://www.suseblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bernard</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-125516</link>
		<dc:creator>Bernard</dc:creator>
		<pubDate>Fri, 15 Aug 2008 00:03:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-125516</guid>
		<description>Thanks for that step by step tutorial.  Worked perfectly.  I hadn&#039;t used SuSE for about 7 years (SuSE 5.4 or 5.6 was the first Linux distro I ever got installed).  I recently returned to using OpenSuSE 10.3 and have found it very good indeed.  I have plans to use SuSE in a deployment of hundreds of servers.</description>
		<content:encoded><![CDATA[<p>Thanks for that step by step tutorial.  Worked perfectly.  I hadn&#8217;t used SuSE for about 7 years (SuSE 5.4 or 5.6 was the first Linux distro I ever got installed).  I recently returned to using OpenSuSE 10.3 and have found it very good indeed.  I have plans to use SuSE in a deployment of hundreds of servers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Morris</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-114393</link>
		<dc:creator>Scott Morris</dc:creator>
		<pubDate>Tue, 24 Jun 2008 15:03:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-114393</guid>
		<description>Robb,
Glad to help out!  Have a good one and thanks for stopping by.</description>
		<content:encoded><![CDATA[<p>Robb,<br />
Glad to help out!  Have a good one and thanks for stopping by.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robb</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-114317</link>
		<dc:creator>Robb</dc:creator>
		<pubDate>Tue, 24 Jun 2008 04:55:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-114317</guid>
		<description>Great tutorial.  I am very green to all this and was able to follow it with ease.  Thank you.</description>
		<content:encoded><![CDATA[<p>Great tutorial.  I am very green to all this and was able to follow it with ease.  Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michal Zugec</title>
		<link>http://www.suseblog.com/opensuse-linux-103-signing-self-generated-ssl-certificates-as-your-own-certificate-authority#comment-112221</link>
		<dc:creator>Michal Zugec</dc:creator>
		<pubDate>Mon, 09 Jun 2008 20:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.suseblog.com/?p=339#comment-112221</guid>
		<description>And for those who likes UI (and YaST) there are yast2-ca-management and yast2-http-server modules ;-)</description>
		<content:encoded><![CDATA[<p>And for those who likes UI (and YaST) there are yast2-ca-management and yast2-http-server modules <img src='http://www.suseblog.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
