SSL connection error
Unable to make a secure connection to the server. This may be a problem with the server, or it may be requiring a client authentication certificate that you don't have.
Practical question - let's say you spin new EC2 on AWS. This results in VM generating new host sshd key for this instance as part of bootstrapping new instance process.
How do you place host sshd key in DNS records without first connecting to this instance and getting the key, action which requires you to check/verify host sshd key (which is NOT in DNS yet)?
Interesting, actually what you mention is not an accounting per se, but I agree with you, specifically
>> 1. Pre-processing data for the entry.
For this specific example if the accounting package does not support certain depreciation method (which rather rare), you can easily do this in Excel, both for financial modelling purposes and as a supporting document for the accounting entry.
>> 2. Post-processing data.
What you describe is not accounting. This is financial and management reporting. Yes, Excel is what is used by most everyone.
>> Invalid point: Formulae are easy to follow and audience can easily verify/reproduce your work.
Actually this is another valid point of Excel.
Unless the financial model was done incorrectly (using VBA, complicated formula chains, unclear logic), it is very easy to verify financial model in Excel, which is a big plus.
I would be curious to know for which sort of accounting things Excel is ideal?
Sorry, I could not comprehend the second paragraph.
Fraud has nothing to do with paper or computer based system. To minimize risk of fraud you need to implement proper sets of controls, like segregation of duties, etc.
As for Excel - Excel is a poor instrument for doing the accounting, therefore it shall not be used ... unless you have some kind of micro/nano business.
>> I still believe that using PFS, even with this limitation, is safer ...
I definitely agree, the problem is that usually there is more than 1 web server :-)
>> The standard is still to point clients to a single termination endpoint, and do active/passive cluster, so that there's no need to share the session tickets.
Sorry, I did not understand (esp. the active/passive cluster thing) - could you please may be add some pointers (blog post, etc) with more details?
Julien, do you have any news to address this Adam's point:
>> So how do you run forward secrecy with several servers and support session tickets? You need to generate session ticket keys randomly, distribute them to the servers without ever touching persistent storage and rotate them frequently. However, I'm not aware of any open source servers that support anything like that.
In my humble opinion the guy is a great engineer who is bored (by lack of challenging projects) and discouraged (by less than stellar teammates).
It is rather easy to check though - you should forget about time spent on work and need to compare the outcome, i.e. result, of this guy vs every other engineer on the team.
If the check above shows that this guy is better than everybody else, than this:
>> Alarmingly often, he'd have hacker news, or dzone open and would be reading articles (I mean 50%+ of the time, not once or twice a day).
and this:
>> More than one of his coworkers have mentioned something along the lines of "can't we fire him 4 weeks out of 5 ?".
indicates one simple thing - he is not managed properly by his manager and by the company.