5 ms·
Why did they need customer private keys for revocation? That didn't make sense to me. [edit: thanks, cjalmeida]
by 1001101 9y ago
Why did they need customer private keys for revocation? That didn't make sense to me.
[edit: thanks, cjalmeida]
- cjalmeida 9y agoYou need private key for the certificate management protocol. Maybe the had some arrangements for automatic revocation back when Symantec was running the CA. Anyway, you are compromising security over convenience. A trade-off IT should never accept.
- cdancette 9y agoNever is a bit harsh, we're all doing it every day. Why are we still using passwords in 2018? They have been proved unsafe by now.
- cjalmeida 9y agoGranted, but in corporate IT, where stakes are higher, those concession should be minimal. Like, setting up a certificate with only a CSR is server setup 101.
- cdancette 9y agoYes, everything is a matter of finding the right compromise (ofc I agree that sending 23000 private keys over email should never be considered)