@bensummers Might you be able to help @dsilverstone out with this problem? blog.digital-scurf.org/2012/… (As you’ve done things with SSL before…)
1
@jogbert @dsilverstone Should be possible, but you'll be fighting infrastructure all the way. Make a CA for client, sign client certs.
1
Replying to @bensummers
@bensummers @jogbert Thanks for the encouragement. Not sure how I can generate the client cert without access to the client's private key :(

Sep 1, 2012 Β· 8:08 PM UTC

2
Replying to @dsilverstone
@dsilverstone @jogbert But ask a real cryptographer, not just someone who plays one on the twitters.
1
Replying to @dsilverstone
@dsilverstone @jogbert They can generate a self-signed cert, then you check validiy and the public key matches the ssh key.