Proxmox SSL Security Discussion - Mailing List Contribution

2017

30 November 2017

Event

N/A

What

Proxmox

proxmox ssl https security mailing-list open-source sni certificate isgroup senior-security-researcher

On November 30, 2017, Francesco “ascii” Ongaro participated in a technical discussion on the official Proxmox project mailing list, published on the lists.proxmox.com site. As Senior Security Researcher at ISGroup, Ongaro criticized the absence of HTTPS protocol for the download.proxmox.com domain, publicly reporting that the SSL certificate had a Common Name inconsistent with the domain and suggesting the adoption of SNI to improve communication security. His intervention gained consensus in the community, highlighting his public commitment to adopting security best practices even in prominent open source projects.

Archived PDF document