4 ms·
I'm confused. The web has a new server. If I trick the server into thinking that stuff I write gets hosted on example.com, it will generate a certificate asse
by thisrod 11y ago
I'm confused.
The web has a new server. If I trick the server into thinking that stuff I write gets hosted on example.com, it will generate a certificate asserting that I have a right to post stuff on example.com. It's easy for me to get that certificate revoked, but hard for the legitimate owners of example.com to do so.
Comparing this to self-signed certificates, I can think of a bunch of drawbacks, but I can't see any advantage. I hope I'm missing something.
- an_ko 11y agoPart of getting a certificate from Let's Encrypt involves getting a file from them that you then serve from a certain URL on your domain. Someone without enough control over your server to be able to do that won't be able to issue a certificate for it. This is called a "domain-validated" certificate. It's not self-signed: Let's Encrypt is a certificate authority, which signs the certificates it issues.
- wielebny 11y agoIt it also possible to perform DNS validation, which is my preferred method as I can automate certificate generation/replacement from Ansible.
- mastax 11y agoI think their point is that any connection that LE makes to example.com in order to verify ownership will be insecure and thus vulnerable to MITM. Not a problem specific to LE, but to any DV cert.