| ▲ | bob1029 4 days ago | |
Think of the out of band layer as two human executives exchanging URLs and GUIDs in person. You still need a secure transport, but in this model the thing that is being secured on the wire expires within 15 minutes. The only way to break the model is to defeat a transport or protocol key and only before rotation, revocation and expiration can catch up each time. | ||
| ▲ | SahAssar a day ago | parent [-] | |
So, that'd be the same for a private CA with short lifetime certs used with TLS, right? | ||