Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Notorious b.s.d.
Jan 25, 2003

by Reene

Sniep posted:

well, a good use of self signed in the wild is intranet/corp poo poo where they run a CA and push the root to alt heir machines like i said earlier. but that's about it.

but i digress heavily

it has already been pointed out that this is not an example of a self-signed cert. it's just a non-standard CA.

with that out of the way, people don't run internal CAs anymore. too much effort

we live in the age of byod. workers have smartphones, tablets, and unmanaged laptops that all need to be able to reach intranet applications. nobody can manage installing and revoking CA certs for a dozen versions of a half-dozen platforms (windows, osx, linux, android, ios, winpho, blackberry). it's just way too fuckin hard

given the choice between accidentally training everyone to ignore ssl errors 100% of the time, and just spending money for public certs on internal services, most people choose to spend a few bucks

Adbot
ADBOT LOVES YOU

Shaggar
Apr 26, 2006
byod is dumb

Shaggar
Apr 26, 2006
also you would only need a public cert for the external endpoint the byods come in on and then any work they do from then on would be on internal machines which have your own roots.

unless u r suggesting you let them store sensitive company materials on their personal, virus infested clunkers.

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

how emblematic of linux in general is it that this thread devolves into caremad argument posting every 3 pages

jre
Sep 2, 2011

To the cloud ?



ruby idiot railed posted:

keep loving that chicken self-signed ssl stymie

Shameful ssl posting itt.

ZShakespeare
Jul 20, 2003

The devil can cite Scripture for his purpose!
this thread is like linux








































a pos

Phoenixan
Jan 16, 2010

Just Keep Cool-idge

Shaggar posted:

byod is dumb
agreeing with shaggar.

VAGENDA OF MANOCIDE
Aug 1, 2004

whoa, what just happened here?







College Slice

Phoenixan posted:

agreeing with shaggar.

Shaggar was right

qntm
Jun 17, 2009
so is it just "deb" now

Sassafras
Dec 24, 2004

by Athanatos
.

Sassafras fucked around with this message at 00:51 on Nov 25, 2014

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Notorious b.s.d. posted:

but that just moves the problem to dns. what the gently caress clients support secure dnssec reliably? who the gently caress publishes secure dns records?

quote:

; <<>> DiG 9.4.3 <<>> cia.gov ANY +dnssec
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41260
;; flags: qr rd ra; QUERY: 1, ANSWER: 26, AUTHORITY: 0, ADDITIONAL: 5

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4000
;; QUESTION SECTION:
;cia.gov. IN ANY

;; ANSWER SECTION:
cia.gov. 16 IN A 23.7.115.36
cia.gov. 86396 IN NS a22-66.akam.net.
cia.gov. 86396 IN NS a13-65.akam.net.
cia.gov. 86396 IN NS a16-67.akam.net.
cia.gov. 86396 IN NS a3-64.akam.net.
cia.gov. 86396 IN NS a12-65.akam.net.
cia.gov. 86396 IN NS a1-22.akam.net.
cia.gov. 14230 IN SOA a1-22.akam.net. monrpt.cia.gov. 2014010907 7200 3600 2419200 14400
cia.gov. 86230 IN MX 10 mail2.cia.gov.
cia.gov. 86230 IN MX 20 mail1.cia.gov.
cia.gov. 86230 IN TXT "v=spf1 mx a:mail1a.cia.gov a:mail1b.cia.gov a:mail2a.cia.gov a:mail2b.cia.gov mx:cia.gov mx:ucia.gov ~all"
cia.gov. 16 IN AAAA 2600:1403:2:194::184d
cia.gov. 16 IN AAAA 2600:1403:2:189::184d
cia.gov. 16 IN AAAA 2600:1403:2:197::184d
cia.gov. 16 IN RRSIG A 8 2 20 20141122103932 20141119093932 840 cia.gov. GdWiXVfdlrwkBmHMPjok16XrSMB9zQLyQyqWbeF5U/6aXusYu84+lXNB FkTaEeHJu5rwOlqK7A5j6Sm3IMT4nduxsF1XnCFDZIK4z6fu1WT6qhVk kN/B/g/KaGOMNoT5+jyN6pSg+BGjtCoiRHhd6A/prxeor2HCL62ljv+L noo=
cia.gov. 16 IN RRSIG AAAA 8 2 20 20141122103932 20141119093932 840 cia.gov. k3sizZgti7m4ZiTWHnFB/9vMmXOF+jJv5YZnOtcRxF5Z6FcekoWENNf9 J2OgQ8SoOlwuMNHQUtnEzkPe0zy13hVDCWcyrrcfz6OTMymGw/nSHifj YtRySBOr3MfJigTxxMMW1c4x3Dgx4hPx6MN3ikazpTvrBF80zrAvhXXJ gSo=
cia.gov. 86396 IN RRSIG NS 8 2 86400 20141122103932 20141119093932 840 cia.gov. xPK3jqw2J5aw7JCmE1YzF0m3k3so3mSg6TcUD6epXLp6O5VVhZINn8e2 KcvPVLiZ8PVsUUXUnD0phDhDDm4ZdQ6Qx/LW57m7v7CuBWHW5qSFJtu4 fliVb+gNihVHMi8jV6imk+6XsvakbLADU/HVWr2oF3nRxyPuFBzvvwMo egw=
cia.gov. 14396 IN RRSIG SOA 8 2 14400 20141122103932 20141119093932 840 cia.gov. TGEPCDL7Ekewd0UFs6CJrSsH/C/zVeD48ml7sh5PyFMQ6sbCYWgMLXY+ 98+K6X4xXdWoB5SDiP7Z8hX3WaKs7UnpMVjPF0/TSjuPu538Gs8R0it/ nigYVOHsmylD5BDOOqOjuV8QqEjCUq8Ar+4CmVP0F/HheYu1HdvAc9Lz kmI=
cia.gov. 86396 IN RRSIG MX 8 2 86400 20141122103932 20141119093932 840 cia.gov. Jk57RvjmG+ZY3/bTMjcdpYm7AZaV5Hz1BP25prcbP+AMgPQL+IsDDCe8 2UR1tq/9xmd0CWyAqFS2OSMYsQfJIw/6Fiz2mwhHvZyEv6H2EvO+1g6D OqkJ9o/Zj/gwTFfFpvvp0BbjmNh66xaU35MeGfpyObKQLwF5mobM6dyZ yhk=
cia.gov. 86396 IN RRSIG TXT 8 2 86400 20141122103932 20141119093932 840 cia.gov. KpZpTzIdEPZGQvdFbSOerRyt/YFIT2WSl4y8yE/vPXFiDBos2rid/rV+ 3RbA/mX1rzEX9MdCydw57kpDVksKvplhCWv5+M5mGu0Ga+70aFU5JVz/ njXxubSyhZoGbSZ/Z8c3txuawupSikBbUXgI1IaWhQRcRi3ehIOnrM6+ xiE=
cia.gov. 7196 IN RRSIG DNSKEY 8 2 7200 20141122103932 20141119093932 45298 cia.gov. Hw7s/A3/AKxwjwobIGji/jQzmwvPSbcCjYPjuU7aAeJUyLjSBCBt7ANU AHEz8YMlYPzI3kx4ftpAsMTrw8DK6TqsTM65Q9Ro7a8rdq4vtc7By3Of yQyu/kmluP1GLXCCSRfqLKROaYhQ8VpC3vCI1yxZ1jXBN+Dv6rKOXRgb 7oxN+lU9aOP13+tfUJSQl/8aNL4y+G2RRD7j5yJz8VB+z7SS+609An6X bmwgAzvXaTjBzT5E7Y3w8+HpDR8vum1XvnNAAJ0sikSQ1FITBbCPuaxY wv0hxjuRbShABK0Ncc8FLGNMOOCf5lg+Bc3K61w59oD1clyKl9TN+Cks aU+QlQ==
cia.gov. 14396 IN RRSIG NSEC3PARAM 8 2 14400 20141122103932 20141119093932 840 cia.gov. AmAl8mNlsT52Kw10wLbUk8YU5qoW+9flSX83tkm+cT2amBMD9q/I9Tbq t8cAWq4FffpVimvyQ3kg5EP7cNSgso0cLOMgGvPqlMQPW0pMrB0CZ5Lt NacepCEYiR/57IsiKrtKdda42Vtg8Tpw4J9yUIjU1F4V5NRslphOm3M8 3jk=
cia.gov. 7030 IN DNSKEY 256 3 8 Av//xvEDoOMBcoGNdmg1JJ4IUuaRUM93zqivZdShdr4ItkJTdwaYVG3I U1SlHIML1lz/2ahte7hf0gNOuXJyuZPwsB3fgtiSh9/Zs1rWjKNQ37jR B33d6M2Cf6taS0xhdjDcW8IoGxwn8ZDucLKvWZspF2+vBv+9M80moKGa yXaq0FE=
cia.gov. 7030 IN DNSKEY 257 3 8 Av//yFz7jN6jiagBJGVlHuCYAo7+BZZEAgQAuOnAfzhUznJdgKctO2za JgTVZTf7J3d8vhSV6zmShXp68j+2x5/tIkA4+oY2sBpxDYYN8yai2MPX 0M//pZHIxoPli4zdjPYxmtLpOvhpDv81lz9eiZJ6kHu1dZffdKn8qze5 r+BNeM/1icbq52UIdwEqmuHvIGNYyjpS7D6YvovuQzxCdILDBs0eGpKA yqw2E2YyqkZxB+LztTLQ8VXKJlUeLfUB0caxqX+g10yfNxDeJOx2G2H6 iUPAd8ldF1pw/69FJaegjSkV1T/Dh+zCrFntCnyv9LQQgZD6oHSmJwBo 1F4PECkLxw==
cia.gov. 7030 IN DNSKEY 256 3 8 Av//tOm8UhP6rCVSr02v3MFZtQxQJUei8XBus6X0DGBSSAOgVScfOKpK 5utDHhr/TWKvRpSk36JnKMJXgsexSn8nnBPxJVZm65p4jvNHdVWbtZ7j Qnl1RzjhL44GFtYjTBJTkZb/dF2m4muW/btkxscg/fB4VwFBHcoZSCQc n95aB90=
cia.gov. 14230 IN NSEC3PARAM 1 0 1 BCAB91CC582377E8

:nsa: doesnt though. they also list please_set_email.absolutely.nowhere as their contact email :|

Captain Pike
Jul 29, 2003

IPvSH6T posted:

:nsa: doesnt though. they also list please_set_email.absolutely.nowhere as their contact email :|

I was once offered a government job admining an important (state) government server, using an obscure system I had never heard of. I had also never adminned a server of any kind. I was told, "You can just learn as you go. C'mon, you'll get long lunches and a nice salary! No one else here knows what they're doing anyway."

Zombywuf
Mar 29, 2008

Jesus gently caress, everyone is wrong about PKI.

Zombywuf
Mar 29, 2008

*complains about self signed certs*

*sshes into newly created EC2 instance*

jre
Sep 2, 2011

To the cloud ?



Zombywuf posted:

*complains about self signed certs*

*sshes into newly created EC2 instance*

*gets warning about unknown remote host because its insecure and could be mitm

Zombywuf
Mar 29, 2008

*ignores warning and continues anyway*

minivanmegafun
Jul 27, 2004

I haven't read any of this thread except the last three pages and it's been a lot of careposting about CA infrastructure that we also discussed in the yossec thread

the difference is that it was on topic in that thread

and also didn't contain a bunch of idiot hell fuckers that don't understand the difference between a self-signed cert and a private CA

and the conversation moved on within like four posts

I came here to look at bad screenshots and maybe read arguments about sysv unit and systemd or maybe rpm and dpkg but noooooo

Zombywuf
Mar 29, 2008

systemd sucks
rpm sucks
ssl sucks

Forums Terrorist
Dec 8, 2011

all linuxes and unixes suck

especially mac os ten dot ten

OldAlias
Nov 2, 2013

actually they are all Good


is this really what u want

http://esr.ibiblio.org/?p=1046
http://esr.ibiblio.org/?p=1573
http://esr.ibiblio.org/?p=184
http://esr.ibiblio.org/?p=4270
http://scienceblogs.com/deltoid/2009/12/01/quote-mining-code/
http://www.catb.org/~esr/aim/
http://rationalwiki.org/wiki/Eric_S._Raymond

minivanmegafun
Jul 27, 2004

ESR is such a goddamn creep

Kiwi Ghost Chips
Feb 19, 2011

Start using the best desktop environment now!
Choose KDE!

Zombywuf posted:

*ignores warning and continues anyway*

mitm chances on initial login are infinitesimal and if the fingerprint ever changes ssh refuses to connect

Sapozhnik
Jan 2, 2005

Nap Ghost
yeah sslchat is pretty offtopic but every yospos thread eventually degenerates into foodchat anyway

this one time i ate an entire jar of mayonnaise

just spooning it out with my bare hand like an animal

Kiwi Ghost Chips
Feb 19, 2011

Start using the best desktop environment now!
Choose KDE!

that's extremely relevant to the desktop linux thread tho

ZShakespeare
Jul 20, 2003

The devil can cite Scripture for his purpose!
linux is to oses as pineapple is to pizza toppings.



for those with terrible taste

Soricidus
Oct 21, 2010
freedom-hating statist shill
I put beans in chili

Zombywuf
Mar 29, 2008

Kiwi Ghost Chips posted:

mitm chances on initial login are infinitesimal and if the fingerprint ever changes ssh refuses to connect

Clearly you've never worked with AWS. I make initial logins every day, hopefully no-ones hacked my router.

Zombywuf
Mar 29, 2008

Mr Dog posted:

yeah sslchat is pretty offtopic but every yospos thread eventually degenerates into foodchat anyway

this one time i ate an entire jar of mayonnaise

just spooning it out with my bare hand like an animal

the most disgusting part is not making your own mayo

Notorious b.s.d.
Jan 25, 2003

by Reene

Zombywuf posted:

the most disgusting part is not making your own mayo

Notorious b.s.d.
Jan 25, 2003

by Reene

Shaggar posted:

also you would only need a public cert for the external endpoint the byods come in on and then any work they do from then on would be on internal machines which have your own roots.

unless u r suggesting you let them store sensitive company materials on their personal, virus infested clunkers.

the terrible thing about byod is that you don't have a choice. people are gonna do what they're gonna do, and if you try to stop them from doing it, they just get mad as hell

e.g. enterprise poo poo for ipad/iphone came about because executives were gonna use an ipad/iphone no matter what IT said. this happened in every fortune 500. IT mgmt had zero choice on the matter

Sapozhnik
Jan 2, 2005

Nap Ghost
i thought byod is what you call it when ppl browse facebook on their phones instead of being pissed off that it's blocked by websense on their pcs

Shaggar
Apr 26, 2006

Notorious b.s.d. posted:

the terrible thing about byod is that you don't have a choice. people are gonna do what they're gonna do, and if you try to stop them from doing it, they just get mad as hell

e.g. enterprise poo poo for ipad/iphone came about because executives were gonna use an ipad/iphone no matter what IT said. this happened in every fortune 500. IT mgmt had zero choice on the matter

for ipads/iphones there are management tools so you can lock down their devices if they're on your network and since they're closed source you can trust them. w/ android or just a regular old laptop you aren't gonna be able to lock them down so your choice are don't allow them or let them be used as thin clients that access ur network thru a vpn and remote desktop/app virtualization

Shaggar
Apr 26, 2006

Mr Dog posted:

i thought byod is what you call it when ppl browse facebook on their phones instead of being pissed off that it's blocked by websense on their pcs

byod has 2 meanings
1) "Hey, im the ceo and I want my email on my personal iphone"
2) "hey, we aren't going to buy you a computer, but you can totally use your personal laptop to do your job!"


1 is legitimate and easy to handle securely in a few different ways.

2 is most often a sign of a bad company

VAGENDA OF MANOCIDE
Aug 1, 2004

whoa, what just happened here?







College Slice
even the case 1 byod is just mark down a "i told u so" somewhere, shrug, and move on :[

The Management
Jan 2, 2010

sup, bitch?
haven't read any of this thread but we're 100 pages in and the year is nearly over and I'm not getting a very good feeling about 2014 actually being the year of Linux on the desktop.

good effort, though. better luck next year.

Zombywuf
Mar 29, 2008

2014 is the year we just gave up on computers being secure

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Notorious b.s.d. posted:

the terrible thing about byod is that you don't have a choice. people are gonna do what they're gonna do, and if you try to stop them from doing it, they just get mad as hell

e.g. enterprise poo poo for ipad/iphone came about because executives were gonna use an ipad/iphone no matter what IT said. this happened in every fortune 500. IT mgmt had zero choice on the matter

*bing*bong* your dumb opinion is being paged to return to http://forums.somethingawful.com/showthread.php?threadid=3564747 *bing*bong*

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

Cocoa Crispies posted:

*bing*bong* your dumb opinion is being paged to return to http://forums.somethingawful.com/showthread.php?threadid=3564747 *bing*bong*

lol that thread

current topic: all users a special snowflakes UGH

pram
Jun 10, 2001
notorious bad poo poo dumbass

Adbot
ADBOT LOVES YOU

VAGENDA OF MANOCIDE
Aug 1, 2004

whoa, what just happened here?







College Slice
dsyp :tipshat:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply