3 ms·
One great advantage of wildcard certificates is the privacy of the domains. If you use customer1.mycorp.com, customer2.mycorp.com, etc. the names of your clien
by chtitux 9y ago
One great advantage of wildcard certificates is the privacy of the domains.
If you use customer1.mycorp.com, customer2.mycorp.com, etc. the names of your clients is exposed twice :
- if you issue one certificate with all the domains, all the domains are readable in the certificate (Cloudflare free cert. has this issue too)
- all the LE certificates are published in Certificate Transparency logs. So you can detect if anyone issues a cert. for your domain, but anyone can view the certificates you issued.
With a wildcard certificate, the subdomains used are not public.
Note this issue applies to "internal" subdomains too. You probably don't want to expose the hostname of your backoffice (admin.mycorp.com) or your new top secret project (linux.microsoft.org).
- overint 9y agoWould you not be exposing those subdomains via DNS anyway?
- ec109685 9y agoThat could be wildcard as well.
- chtitux 9y agoYou can't enumerate sub domains via DNS (except if you use DNSSEC with NSEC algorithm, but nobody do that). It does not prevent people guesssing it tough.
- tptacek 9y agoCorrection: you can also enumerate through NSEC3, the most common (and default) mode of deployment; NSEC3 turns enumerable zone entries into the equivalent of a password hash file, which can be cracked. There's a hack to prevent this that seeds the zone with false entries, but it requires the server to operate as an online signer. Since this is essentially incoherent to the design of the protocol (which makes major cryptographic and usability sacrifices to enable offline signers), there's an "NSEC4" being worked on now. DNSSEC is silly.