3 ms·
I'd definitely read more about how to do it properly. For example I wonder how CAs (e.g. Let's Encrypt) secure their infrastructure.
by Shoothe 9y ago
I'd definitely read more about how to do it properly. For example I wonder how CAs (e.g. Let's Encrypt) secure their infrastructure.
- jlgaddis 9y agoA good start would be reading their CPS.
- pharaohgeek 9y agoIf you're referring to a properly run CA, then they're a good model to follow. Some of them, obviously, do not implement proper operational security procedures, but a good many of them do. It's usually required in order to have your Root CA certificate added to the trust store of major browsers, OSes, etc. I was a senior engineer for one of the larger commercial CAs, and started off my career as an engineer for the world's largest gov't CA. Biometrics, HSMs (hardware security modules) for storing the keys, offline root CAs, documenting EVERYTHING, armed guards, etc. are the norm. The CA software platforms themselves are usually assessed for FIPS, Common Criteria, etc. compliance. And we were audited. All. The. Time. I can't speak to Let's Encrypt, but the bigger companies that make their money in the CA space are insanely serious about security.
- Shoothe 9y ago> I can't speak to Let's Encrypt, but the bigger companies that make their money in the CA space are insanely serious about security. That's really what I'm interested in, very high level security / operations standards. Not that I'm intending on running the CA myself but it's easier to understand daily trade offs knowing how it would be done if extremely high standards were absolutely necessary. Unfortunately there is not much reading material online on this subject (I understand it may not be super interesting subject for most people) but reading the CPS really shed some light. Thanks for your comment!