4 ms·
How about distributing Let's Encrypt? Do cloud hoster offer a copy of the service from their datacenter? Otherwise it could be a single point of failure / sing
by frik 9y ago
How about distributing Let's Encrypt?
Do cloud hoster offer a copy of the service from their datacenter? Otherwise it could be a single point of failure / single attack vector, right?
- pjc50 9y agoDistributing a CA makes it less secure, not more; ultimately the thing that "is" a CA is the private key, which ought to be stored in a HSM and never let out.
- sova 9y agoMirroring Certificate Authorities seems to create more potential security holes...
- stephenr 9y agoTheir infrastructure is meant to all be HA from memory, and unless you're doing stupid things like caddy did[1] small windows of downtime shouldn't cause much issue for ongoing operations anyway - you will likely be starting to attempt renewing certs weeks before they expire. 1: https://github.com/mholt/caddy/issues/1680 https://github.com/mholt/caddy/issues/1680
- hkeide 9y agoWow, that Caddy thing is pretty scary, thanks for pointing it out. I wonder what other decisions like that lurk under the surface.
- frik 9y agoI meant a clone/copy of the (hopefully open) server software of LetsEncrypt stack running as a service on several well known cloud datacenters - of course under a different name. Why? Not a single point of issue. Given now that it has now 25% market share, it's a high profile target, and given he short cert lifetime aggressive updating is necessary meaning you could receive a underhanded cert in case someone gets access to the high profile target. If Let's Encrypt is not a startup and doesn't plan to make money, then there should be no problem to release the whole service as DEB/package so that every big hosted can run a clone under a different name. Or is LetsEncrypt in the business of gathering analytics and selling the usage data? I think no.
- pfg 9y agoJust to clarify, do you want to give every one of those big hosters the keys to the internet, as in either a new root CA or one that's cross-signed by an existing CA? If you're not giving them that, I'm not sure what they would do with just the CA server (which is indeed open source, by the way.) If you're giving them the keys ... well, do you really want to trust every single big hoster with the keys to the internet? They would still have to pass (very expensive) audits, apply for root inclusion, etc., so it wouldn't be as simple as running the Let's Encrypt server stack. Amazon and Google run their own independent CAs already, with Amazon offering free issuance as part of some of their products (with non-extractable keys). I'd expect Google to offer something similar in the near future. I'm reasonably confident that these companies know how to run a CA, but I'm not sure I would trust many other hosters with something like that.