Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: Gentoo mailing list <gentoo-user@l.g.o>
Subject: Re: [gentoo-user] {OT} Allow work from home?
Date: Wed, 20 Jan 2016 00:19:13
Message-Id: CAN0CFw1rBa6QkwVOszYFtzN56QMN61+kKaBi_OsSKmjS47dMGA@mail.gmail.com
In Reply to: Re: [gentoo-user] {OT} Allow work from home? by Rich Freeman
1 >> You can use apache client authentication with SSL certificates only. Of
2 >> course you will need to create a self-signed CA, which you will use to create
3 >> the web server public/private key pair and also sign each client's certificate
4 >> and upload it along with your CA certificate to the user's browser. This
5 >> explains the principle:
6 >>
7 > Now, a solution a more traditional desktop is to use an SSL key stored
8 > on a smartcard, which I'm sure Diego has blogged about on
9 > planet.gentoo.org as he is into those. That has all the advantage of
10 > the TPM as far as key security goes. However, you're still vulnerable
11 > to xss and keyloggers and such.
12
13
14 Is an SSL key stored on a smartcard better than a TOTP password? They
15 seem roughly equivalent to me. I don't think either would restrict
16 access by device.
17
18 - Grant

Replies

Subject Author
Re: [gentoo-user] {OT} Allow work from home? Rich Freeman <rich0@g.o>