4 ms·
If one absolutely must regardless please use name/IP constraints! Client support isn't super awesome from what I understand but it's much better than having an
by ehPReth 9y ago
If one absolutely must regardless please use name/IP constraints!
Client support isn't super awesome from what I understand but it's much better than having an unconstrained root ('keys to the internet') on >1 client - especially if you can't go the nines to protect said key.
- bandrami 9y agoWow, you guys have very different use cases from me. We do all internal authentication through server and client certificates. I'm still astounded that people seem to want a third party to participate in internal trust relationships, which seems just like a really bad idea to me.
- detaro 9y agoThey don't want a third party in internal trust relationships, but they want to avoid their internal trust being used to attack their communications with the outside even more. Locally added CA certs override even features such as key pinning, so if your local CA gets compromised it can be used to MITM everything. Not everyone trusts themselves to run a CA safely enough, or to make it properly available to developers.