3 ms·
Not only that, but they're doing things like Certificate Transparency - publishing every certificate they sign into public logs and they're funded and supported
by problems 9y ago
Not only that, but they're doing things like Certificate Transparency - publishing every certificate they sign into public logs and they're funded and supported by some of the biggest names in online security and privacy.
They're probably the most trustworthy CA on the planet.
- peterwwillis 9y agoConsidering that literally anyone who gets even local access to any server at all, or can spoof one - even servers that have never used LetsEncrypt before - can generate new valid LetsEncrypt certificates, and nothing generated has a password on it, I don't know if I would consider them trustworthy. If you want to passively monitor encrypted traffic on a massive scale and not get caught (other than via their log - and who is reading that to see if every server they have has been issued a cert unnecessarily, anyway?), LetsEncrypt is awesome. It's plausible to do this without LetsEncrypt, but they made it a lot easier.
- gruez 9y ago>Considering that literally anyone who roots any server at all - even servers that didn't use LetsEncrypt before - can generate new valid LetsEncrypt certificates As opposed to any other CAs? There are plenty of other CAs that will happily grant a certificate if you prove control of a server that the domain resolves to. >nothing generated has a password on it, I don't know if I would consider them really trustworthy. If you have root on the server, can't you just dump the certificate out of memory, even if there's a password on it? short of using a HSM, you need the certificate decrypted so the server can use it.
- peterwwillis 9y agoWell I have a problem with the fact that you can't stop random CAs from issuing certs for a domain you own. But I don't think that's changing anytime soon. Passwords provide security for data at rest, a properly hardened server makes it very difficult to dump memory in certain circumstances, and hsm are practically a requirement in some environments. And finally, say I wanted to use LetsEncrypt, but I wanted to manage the keys myself, and require only private key X could be used to sign Y, and manage it myself. They don't really let me set those requirements at the CA level - it's all on my own host + network security, which IMHO is unnecessarily risky.
- detaro 9y ago> Another thing is, let's say I use some other CA for my certs, and I don't want LetsEncrypt issuing any. I can't really stop them, can I? CAA records. If you want full control over when issuance happens, you can even set the list of allowed CAs to empty and only change it when you actually want a certificate. > And finally, say I wanted to use LetsEncrypt, but I wanted to manage the keys myself If someone can submit a CSR and complete the challenges they get a signed cert, yes, just like with other DV-CAs. LE code (certbot or other clients) doesn't have to touch your private keys, as long as you give them CSRs, as with other CAs.
- pfg 9y ago> Another thing is, let's say I use some other CA for my certs, and I don't want LetsEncrypt issuing any. I can't really stop them, can I? You absolutely can. Let's Encrypt was one of the first CAs to support CAA (and, IIRC, they supported it when they first launched). CAA is a DNS record that lets you specify which CAs are permitted to issue certificates for your domain. > And finally, say I wanted to use LetsEncrypt, but I wanted to manage the keys myself, and require only private key X could be used to sign Y, and manage it myself. They don't really let me set those requirements at the CA level - it's all on my own host + network security. I'm not quite sure what you're saying here. Do you want the ability to issue certificates under your own (constrained) intermediate certificate? That's unfortunately not possible under the current Baseline Requirements unless you get audited as a CA. If you just want to use your own private key, that's of course possible (in fact, there's no way for Let's Encrypt to generate a key for you). Or is it that you want to limit limit issuance for domain X to key Y? What other CA allows you to do that? And how would you prevent some other CA from issuing a certificate for a different key, even if Let's Encrypt would support such a feature? With that in mind, it becomes clear that in the end it's up to your host and network security again, even with such an agreement in place.
- peterwwillis 9y agoI wasn't aware of CAA, that's a nice development. > Do you want the ability to issue certificates under your own (constrained) intermediate certificate? Look at it this way: currently, if you can send network traffic from some IP space, you can create valid domain certs. This is the equivalent of using a hosts file with a list of IPs to authenticate an ssh connection. Yes, I think an intermediary key, and not simply some arbitrary control of a network, should be required to generate a cert. It seems like CAA, or some extension thereof, could help this become a reality.
- deleted 9y ago[deleted]
- pfg 9y ago> Considering that literally anyone who roots any server at all, or can spoof one - even servers that have never used LetsEncrypt before - can generate new valid LetsEncrypt certificates, and nothing generated has a password on it, I don't know if I would consider them trustworthy. This is true for the vast majority of all CAs. > If you want to passively monitor encrypted traffic on a massive scale and not get caught (other than via their log - and who is reading that to see if every server they have has been issued a cert unnecessarily, anyway?), LetsEncrypt is awesome. Wouldn't you rather pick a CA that doesn't log all certificates publicly? (At least while that's still possible - i.e. till early next year.) If you're doing this on a massive scale with a CA that logs publicly, there is absolutely no way you're not getting caught. Certificate Transparency Monitoring is fairly easy to set up, by the way. Even Facebook runs a public monitor you can use.
- foepys 9y agoA lot of non-EV certs are given out if you control one of about 6 pre-defined email addresses like webmaster@. The security is already lacking given SMTP's bad security architecture and I'd argue that LE's protocol is a lot better.
- detaro 9y agoAnyone who had the necessary access to a server could get a domain-validated certificate before LE existed, they didn't introduce that. You can generate and handle the private key entirely yourself, without ever having LE code touch it if you want. You only need to generate CSRs from it. And you now more than ever have tools to control this if you worry about it: CT logs (that you don't have to check yourself, thanks to free services that alert you about each new certificate for your domain) and CAA records
- vbezhenar 9y agoI think it's a valid criticism, not LE but industry as a whole. Intel should add usable HSM in every cheap laptop, not even talking about servers instead of their ME backdoors. Technology is there, it's cheap and it's needed.
- tatersolid 9y agoNearly all laptops, desktops, and servers sold in the last decade have a Trusted Platform Module (TPM) which is in fact a HSM. You need drivers and utilities to use it but it's there. TPMs generally aren't fast enough to do RSA signatures a on busy webserver though, but they're wonderful for protecting VPN certificates (tools for managing this are built into windows Group Policy, I imagine it's very painful on Linux)
- mandevil 9y agoThat... is the point of the DV cert?