4 ms·
For us the free doesn't matter because certificates are cheap. It's the byzantine and insecure process of obtaining a cert (sending us our private cert in a zip
by teh 11y ago
For us the free doesn't matter because certificates are cheap. It's the byzantine and insecure process of obtaining a cert (sending us our private cert in a zip in a plain text mail. I mean, really?) that makes LE so great.
Edit: Total brainfart, apologies; The company sending us private info as a zip was a different thing.
- pfg 11y agoYour CA should not be in a position to send you your private key. They don't need it in order to sign your certificate. Pretty much every CA I'm aware of allows you to provide your own CSR (which only includes your public key). Sending the certificate (as opposed to the private key) via email is fine, since that only includes your public key, which is visible to every site visitor anyway. (I agree that an automated process based on an open, standardized specification is preferable.)
- nailer 11y agoAgreed a thousand percent, but there are services that offer easy installs onto cloud providers that do know your private key - that's how they get it onto your ELB or Heroku.
- duaneb 11y agoIf you can restrict the service to a subdomain, there are alternatives like the SAN extension that allow those third parties to avoid handling your private key at a small extra cost.
- nailer 11y agoI'm having trouble understanding your comment. SANs are mandatory (current browsers don't even use CNs), how would SANs specifically prevent this? The endpoint where your terminating your traffic obviously must have the private key to decrypt it.
- duaneb 11y agoYou need one cert (or at least only a handful of certs)—SAN entries do not need to be subdomains of the CN. Greatly reduces headache of ssl-terminating for e.g. client domains.