X-Junk-Score: 0 [] X-Cloudmark-Score: 0 [] Return-Path: Received: from poseidon.rz.tu-clausthal.de ([139.174.2.21] verified) by mail.stalker.com (CommuniGate Pro SMTP 5.3.4) with ESMTP id 59095304 for CGatePro@mail.stalker.com; Thu, 11 Mar 2010 08:01:53 -0800 Received-SPF: none receiver=mail.stalker.com; client-ip=139.174.2.21; envelope-from=koch@rz.tu-clausthal.de Received: from poseidon.rz.tu-clausthal.de (localhost [127.0.0.1]) by localhost (Postfix) with SMTP id B6208256AF9 for ; Thu, 11 Mar 2010 17:00:22 +0100 (CET) Received: from tu-clausthal.de (poseidon.rz.tu-clausthal.de [139.174.2.21]) by poseidon.rz.tu-clausthal.de (Postfix) with ESMTP id A12FC256A7E for ; Thu, 11 Mar 2010 17:00:22 +0100 (CET) Received: from [139.174.4.141] (account ok [139.174.4.141] verified) by tu-clausthal.de (CommuniGate Pro SMTP 5.3.4) with ESMTPSA id 51873954 for CGatePro@mail.stalker.com; Thu, 11 Mar 2010 17:00:22 +0100 Message-ID: <4B991396.3070506@rz.tu-clausthal.de> Date: Thu, 11 Mar 2010 17:00:22 +0100 From: Oliver Koch Organization: Rechenzentrum TU Clausthal User-Agent: Thunderbird 2.0.0.23 (X11/20090817) MIME-Version: 1.0 To: CommuniGate Pro Discussions Subject: Re: TLS and Certificates - Updated References: In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable X-Virus-Scanned: by Sophos PureMessage V5.5.9 at tu-clausthal.de Hi, Matthew Black wrote: > Wildcard certificates are NOT the way to go for large enterprises. They= > present a whole set of security problems because some sites offer dozen= s > of services, each with its own certificate. Our university operates > hundreds of servers. If a wildcard certificate gets compromised, EVERY > service loses its security. >=20 > Why can't CommuniGate figure out how to configure multiple certificates= , > say one for each service (IMAP, POP, WebUser) and a different set for > each domain? Apache has been doing this for a very long time. we use a SSL certificate which contains a main common name and several alternate common names. So it isn't a wild card certificate but we have only one certificate to connect to our server (it's only one server) by different hostnames. Perhabs that might be a solution for Dana too? Kind regards, Oliver Koch --=20 Oliver Koch Tel.: 05323/72-2626 | Fax: -3536 Rechenzentrum TU Clausthal E-Mail: koch@rz.tu-clausthal.de Erzstra=DFe 51 WWW: http://www.rz.tu-clausthal.de D - 38678 Clausthal-Zellerfeld Jabber: ok@jabber.tu-clausthal.de