You can't fake the UUID in mTLS because you need the actual private key to be present with the client when it makes a connection to the server. There's no way to fake this in TLS.
You can't fake the UUID in mTLS because you need the actual private key to be present with the client when it makes a connection to the server. There's no way to fake this in TLS.
> Creating a CSR creats my private key for the CSR...
Not really sure what's going on here tbh.
Yeah... No. You create a public/private key pair and the CSR CONTAINS that public key together with additional information.
>Not really sure what's going on here tbh.
I'm not surprised. Go read up on this stuff.
The CSR contains the digital signature of the public key that is requesting the certificate. So you absolutely need the private key to create a CSR. How would you create a CSR with just a public key?
Do you really not know what you're talking about or are you trolling at this point?
Yeah, go read it:
The
certification request information consists of the entity's
distinguished name, the entity's public key, and a set of attributes
providing other information about the entity.> 2. The CertificationRequestInfo value is signed with the subject entity's private key. (See Section 4.2.)
I wonder what this means? Hmm...