Changes between Version 9 and Version 10 of EasyRSA3-Insecure-PKI


Ignore:
Timestamp:
12/16/13 17:52:31 (10 years ago)
Author:
JoshC
Comment:

be less harsh about wanting this

Legend:

Unmodified
Added
Removed
Modified
  • EasyRSA3-Insecure-PKI

    v9 v10  
    1111> If this is insecure, why is this useful?
    1212
    13 Some people are unwilling to create a separate PKI directory for their CA, server, and client. These instructions feel "easier" for people who are afraid of creating 3 PKI directories and generating keys on their client & server, then copying and pasting the request details to the CA system. For people that are afraid of these tasks, this procedure feels more simple.
     13Some people don't want a separate PKI directory for their CA, server, and client. These instructions might feel "easier" for people who are averse to creating 3 PKI directories and generating keys on their client & server and copying and pasting the request details to the CA system.
     14
     15The method described here takes shortcuts to avoid transporting the request, but in return you must transport private keys instead. This is not ideal from a security standpoint, but advanced users may want this functionality for specific use-cases.
    1416
    1517== Procedure ==