Underspecified part in the Specification
Felix Queißner
felix at masterq32.de
Tue May 19 22:08:09 BST 2020
Hey List and especially solderpunk!
I just started to read on the certificate stuff and looked at
Astrobotany [0] as an example application using client certificates.
Their process looks like this:
1. Generate private key
2. Generate a certificate request
3. Submit your CSR via HTTPS to astrobotany, they will then send you a
signed certificate
4. Use that certificate to authenticate at astrobotany
Now i wonder:
Is this the planned way everyone should go? What about self-signed
client certificates?
I would expect Gemini to use self-signed client certificates for
identitiy management, and even more for transient certificates.
The documentation on client certificates is mainly §1.4.3 and the status
codes 61 and 62, but no word about how to obtain these client certificates.
I think this needs some clarification on how to handle this
Regards
xq
[0] gemini://astrobotany.mozz.us/
More information about the Gemini
mailing list