Skip to main content

Questions tagged [client]

In a client-server model, the server serves services to the client.

74 votes
4 answers
21k views

I'm trying to get my head around how PKCE works in a mobile app and there's something I don't quite understand. So from what I can gather the client app creates a random cryptographically secure ...
TommyBs's user avatar
  • 877
16 votes
1 answer
22k views

For an IoT project, I want to secure client server communication. I want both the server (Apache) and the clients identify/authenticate each other (a client won't communicate with other clients) ...
Saren Tasciyan's user avatar
9 votes
3 answers
1k views

In a scenario where there are client RSA certificates (e.g. on a smart card), is it possible to record a form submission (or an AJAX request) in a form which makes it possible to later ascertain that ...
Ivan Voras's user avatar
3 votes
1 answer
3k views

I recently wrote an application that calls out to a 3rd party service to perform some work. This 3rd party service requires that I authenticate the client calling by using a client certificate. For ...
TheTFo's user avatar
  • 133
15 votes
2 answers
20k views

we're in the process of replacing certificates with SHA1 hash due to Google's move to let them appear less secure in Chrome. The replacement certificates use a different intermediate CA than the ones ...
luxifer's user avatar
  • 153
4 votes
2 answers
3k views

How do real HTTPS servers validate client certificates? My context is business-to-business rather than regular human clients. I understand basic chain validation to a trusted root CA cert. But do ...
Harry's user avatar
  • 41
2 votes
2 answers
6k views

We have a proper signed server certificate and intermediate CA from a trusted certificate authority. Is it true that we cannot use this certificate (so the intermediate CA) for creating our own ...
Wilt's user avatar
  • 913
28 votes
5 answers
38k views

Every time that someone mentions eval(), everyone says that there are "security issues" with it, but nobody ever goes into detail about what they are. Most modern browsers seem to be able to debug ...
Stack Tracer's user avatar
20 votes
2 answers
20k views

Client authentication may be used in a SSL/TLS negotiation. For this, the client will send a CertificateVerify after the server requested it. The CertificateVerify message contains the client ...
Duke Nukem's user avatar
11 votes
5 answers
10k views

Imagine that you have a web application that encrypts the user's data, such as a note or spreadsheet, on both the server and client. The normal process for a user using this web application is ...
Joseph's user avatar
  • 215
9 votes
3 answers
17k views

I have a very specific question. A client verifies a server by taking the certificate and checking specific values and that the digital signature of the intermediate CA is correct (according to the ...
Christopher's user avatar
6 votes
2 answers
620 views

For multiplayer (competitive) games, there is often the issue of needing to detect illegitimate players so they can be denied service. On the other hand, legitimate players should of course be ...
Nicholas Miller's user avatar
4 votes
3 answers
1k views

When writing a server sofware, what are the methods used to verificate the user connected to the server is actually using the official client program ? This is to prevent the access to the server ...
Rockybilly's user avatar
29 votes
2 answers
9k views

After installing a CAcert personal certificate, every time I land on the BBC weather site it asks me to identify myself with a certificate. Why would any non-malicious web site do that unless I've ...
l0b0's user avatar
  • 3,045
25 votes
6 answers
7k views

The keygen tag is used to make browsers generate private keys and POST the resulting CSR to the server, which can then issue a certificate. It's now been deprecated, for rather stupid reasons but that'...
André Borie's user avatar
  • 12.9k

15 30 50 per page