|
|
|
|
|
by stephenr
4164 days ago
|
|
explain a real world scenario where you have a web server with a valid certificate but you don't have a DNS entry for the server? You're inventing ridiculous scenarios to justify a nonsense concept of integrating html, browsers and ssh. |
|
For example, if the certificate is assigned to an IP address. Not extremely common, but some people use it. [1]
You're inventing ridiculous scenarios to justify a nonsense concept of integrating html, browsers and ssh.
I stated (twice) that I think having the browser act as an SSH client is a silly idea. Not sure how I'm interpreted otherwise.
Both of my posts only point out that your intended correction (to just use DNS) wouldn't work for all cases, while the original post would work fine for authentication as far as I can tell. And that there are no inherent security concerns using in-band fingerprints, as opposed to looking them up via DNS w/ DNSSEC, if you already trust the integrity of the server response.
You keep replying along the lines of "well it's a bad idea to do SSH in the browser anyways", and I've already agreed with you there, because you're correct.
[1] https://support.globalsign.com/customer/portal/articles/1216...