Objective

Normal SSL/TLS applications are sending the client certificates in plaintext when the client authenticates, which is a privacy issue.

There is now a solution called EncryptedClientAuthentication :

How to do it

EncryptedClientAuthentication (last edited 2008-05-22 22:16:41 by anonymous)