Hacker News new | past | comments | ask | show | jobs | submit login

I doubt e.g. OpenSSH would ever implement something like you describe though. They're seemingly very much against anything x509/WebPKI.



You imply OpenSSH is the place to do this work.

Given the protocol changes needed, it may be a new implementation. I actually expect it would be.


I believe section 7 of RFC 9000 would allow for the creation of a handshake protocol which could conform to SSH without the need for including x509.


Thanks for the tip, wasn't aware of this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: