<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[TLS and SSH rely on Certificate Authorities (CAs) for authentication, but they also present a vector for Man in the Middle attacks.]]></title><description><![CDATA[<p>TLS and SSH rely on Certificate Authorities (CAs) for authentication, but they also present a vector for Man in the Middle attacks. What if you could set up your own CA to reduce your exposure?</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/27a1.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--arrow_right" style="height:23px;width:auto;vertical-align:middle" title="➡" alt="➡" />️ <a href="https://fedoramagazine.org/make-a-private-ca-with-step-ca/" rel="nofollow noopener"><span>https://</span><span>fedoramagazine.org/make-a-priv</span><span>ate-ca-with-step-ca/</span></a></p><p><a href="https://fosstodon.org/tags/WebDev" rel="tag">#<span>WebDev</span></a> <a href="https://fosstodon.org/tags/Linux" rel="tag">#<span>Linux</span></a> <a href="https://fosstodon.org/tags/Security" rel="tag">#<span>Security</span></a> <a href="https://fosstodon.org/tags/InfoSec" rel="tag">#<span>InfoSec</span></a> <a href="https://fosstodon.org/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://fosstodon.org/tags/Fedora" rel="tag">#<span>Fedora</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/ecfe4dc5-5469-45ec-b940-6f7ee3c090f9/tls-and-ssh-rely-on-certificate-authorities-cas-for-authentication-but-they-also-present-a-vector-for-man-in-the-middle-attacks.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 30 Apr 2026 21:51:58 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/ecfe4dc5-5469-45ec-b940-6f7ee3c090f9.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 01 Apr 2026 14:46:15 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to TLS and SSH rely on Certificate Authorities (CAs) for authentication, but they also present a vector for Man in the Middle attacks. on Wed, 01 Apr 2026 15:17:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/ben%40snac.benbuhse.com">@<span>ben</span></a></span> <span><a href="/user/fedora%40fosstodon.org">@<span>fedora</span></a></span> It is possible to do so but this is not the default at least on Debian/Ubuntu based distros. Is this different in Fedora?</p>]]></description><link>https://board.circlewithadot.net/post/https://karlsruhe-social.de/users/giggls/statuses/116330111167878864</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://karlsruhe-social.de/users/giggls/statuses/116330111167878864</guid><dc:creator><![CDATA[giggls@karlsruhe-social.de]]></dc:creator><pubDate>Wed, 01 Apr 2026 15:17:07 GMT</pubDate></item><item><title><![CDATA[Reply to TLS and SSH rely on Certificate Authorities (CAs) for authentication, but they also present a vector for Man in the Middle attacks. on Wed, 01 Apr 2026 15:12:20 GMT]]></title><description><![CDATA[You <i>can</i> use CAs for SSH, e.g. <a href="https://www.lorier.net/docs/ssh-ca.html">https://www.lorier.net/docs/ssh-ca.html</a><br /><br />CC: <span><a href="/user/fedora%40fosstodon.org">@fedora@fosstodon.org</a></span><br />]]></description><link>https://board.circlewithadot.net/post/https://snac.benbuhse.com/ben/p/1775056340.321972</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://snac.benbuhse.com/ben/p/1775056340.321972</guid><dc:creator><![CDATA[ben@snac.benbuhse.com]]></dc:creator><pubDate>Wed, 01 Apr 2026 15:12:20 GMT</pubDate></item><item><title><![CDATA[Reply to TLS and SSH rely on Certificate Authorities (CAs) for authentication, but they also present a vector for Man in the Middle attacks. on Wed, 01 Apr 2026 14:51:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/fedora%40fosstodon.org">@<span>fedora</span></a></span> Huh? ssh does not use CAs it uses a known_hosts file.</p>]]></description><link>https://board.circlewithadot.net/post/https://karlsruhe-social.de/users/giggls/statuses/116330010716836792</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://karlsruhe-social.de/users/giggls/statuses/116330010716836792</guid><dc:creator><![CDATA[giggls@karlsruhe-social.de]]></dc:creator><pubDate>Wed, 01 Apr 2026 14:51:35 GMT</pubDate></item></channel></rss>