3 ms·
That is not entirely true. Perhaps in the stated configuration it is, but since the domain points to the EC2 instance, you could always register a new LetsEncr
by Taranli_Maren 8y ago
That is not entirely true. Perhaps in the stated configuration it is, but since the domain points to the EC2 instance, you could always register a new LetsEncrypt certificate for it, and do a silent MITM.
Perhaps the architecture you describe is the best, however I would hope for two things to be supported:
1) The ability to run your own gateway server instead of having to trust one managed by your company.
2) The ability to disable the gateway entirely if you happen to have a business connection already.
- gsreenivas 8y agoIt's possible but not something we would ever do. We are looking at STARTTLS Everywhere from EFF as means to help ensure that any cert changes would be tracked transparently. #1 is something we will support via open source.
- jakejarvis 8y agoIf running our own gateway server on a cloud provider of our choosing will really be an option, that might sell this for me. Would that remove the yearly $99 requirement? I understand we wouldn’t get support for a lot of the things you handle transparently behind the scenes blacklist/DNS-wise.