pkictl icon indicating copy to clipboard operation
pkictl copied to clipboard

Use openssl random serial for certs

Open ruimarinho opened this issue 10 years ago • 2 comments

OpenSSL provides a secure built-in way of generating random serials for certificates, which avoids possible conflicts.

ruimarinho avatar Apr 13 '15 17:04 ruimarinho

@ruimarinho I'm curious and forgive my ignorance, but does this improve security? To avoid disclosing information regarding the serials? Improve reliability through avoiding collisions?

holmboe avatar Oct 09 '16 20:10 holmboe

@holmboe I think this was simply moving the responsibility of managing the serials to openssl, nothing else. I am not aware of any security implication of the current behaviour (before merge).

ruimarinho avatar Oct 09 '16 22:10 ruimarinho