4 ms·
I agree that wildcards aren't great if they're being passed around an organization to avoid registering a few extra certs, but they are very useful in a few cir
by mnutt 9y ago
I agree that wildcards aren't great if they're being passed around an organization to avoid registering a few extra certs, but they are very useful in a few circumstances such as sandstorm.io: every app session uses a different subdomain to prevent cookie leakage, and registering that many certs would overwhelm LE. I'd imagine there are other cases out there involving automatically created subdomains that will benefit.
- dijit 9y agoLike I said. There are uses for wildcard certs I'm just arguing against the fact they're used en masse. People should be perfectly aware of the ramifications and sandbox appropriately. (*.tennant.sandstorm.io or whatever.) Everyone keeps saying SaaS is the reason for the use of wildcard certs and I would absolutely argue the point that multi-tennancies weakest tenet is the fact that if you get compromised the scale can be broad. Why intentionally weaken that system? LE can handle thousands of domain creations a minute, they've been very forthcoming with lifting limits for people on domain creation. The downside is your server sites which need a little overhead for vhost creation but that could be automated with less than a day of ops work.
- pas 9y agoStoring that many certificates is a total waste of engineering. (On both LE's and the SaaS's side.)
- mnutt 9y agoI believe a while ago the sandstorm people spoke to LE who advised that it wasn't a good idea. I'll stand by the assertion that vhosts are probably still better off with a wildcard cert if it's the difference between a single server using a single cert vs a single server holding thousands of certs. In a node compromise it's the same either way. If different servers are serving different subdomains then sure, subdomain certs are the better way to go.
- ocdtrekkie 9y agoI'll probably finally self-host Sandstorm once I can get a wildcart cert from Let's Encrypt.
- the_common_man 9y agoWas this the main issue stopping you? Wildcard certs are only 45 USD per year.
- ocdtrekkie 9y ago$45 a year from who? I didn't see anything that cheap from anywhere mildly reputable. And yeah, main reason.
- edgan 9y agoAlphaSSL, Google $42 wildcard
- the_common_man 9y agoGarrison host, ssl2buy