5 ms·
If you can't trust a CA not to prevent their official client from becoming malware, then I don't see how you can trust them to maintain their position as CA. Th
by mei0Iesh 11y ago
If you can't trust a CA not to prevent their official client from becoming malware, then I don't see how you can trust them to maintain their position as CA. There is no real scenario where the official client is discovered to be backdoored, and people go on using Let's Encrypt certificates.
- deleted 11y ago[deleted]
- pdkl95 11y agoMalware isn't the problem - their automagic client screwing up my webserver is the problem. This is a justified concern given that the official client already demonstrates bad behavior by causing side effects on --help (see my top level post).
- mei0Iesh 11y agoIt is not a concern at all for me, because I can run that command from a user that does not have privileges to mess anything up. Those options make it not even attempt to read or write any web server configuration. All it does is create the certificate.
- kuschku 11y agoEven worse: It already has screwed up my webserver. Script crashed while trying to verify, left the apache config files in the modified state. Trying to get that back to work took another half hour of the server being down. I’m gonna use the simple website someone made to generate certificates from now on.