5 ms·
Discovery of all the certs is what I think is the harder problem.
by dev_dull 7y ago
Discovery of all the certs is what I think is the harder problem.
- human20190310 7y agoI agree. What can be done to prevent developers from adding a certificate dependency without monitoring during the move-fast-and-break-things days of early development, which then sits for X years as developers come and go, and nobody notices until it fails?
- technion 7y agoWhilst I'll say "disclaimer, this is my project", monitoring Certificate Transparency with CT Advisor has helped me find out about certificates marketing people deployed and expected me to maintain without my knowledge. [0] https://ctadvisor.lolware.net/ https://ctadvisor.lolware.net/
- rhizome 7y ago>What can be done to prevent developers from adding a certificate dependency Discipline? Experience? PIP?
- lvh 7y agoCertificate Transparency works pretty darn well for most usecases, we (Latacora) have found while trying to solve exactly this problem (or at least the figure out which certs exist that aren't being regularly re-issued part) :-)
- tialaramex 7y agoCaveats: Certificates that aren't from the Web PKI almost invariably won't be logged. Most logs explicitly refuse everything except certs from the Web PKI so as not to be burdened storing garbage. So this won't find certs issued by the custom OpenSSL CA on that one guys Linux laptop. Not all Web PKI certs are logged. There is no BR obligation and no root store programme rule that requires logging. The only things in place that strongly encourage logging are the Chrome and Safari policies. For systems that aren't designed to be accessed with a web browser or, much more rarely, enterprises that have persuaded themselves only IE is authorised anyway, the certs might deliberately not be logged. Yes there are (small) CAs doing this in the Web PKI, on purpose, in 2019.
- lvh 7y agoYou can tell ACM your CT preference! (But seriously, sure you’re right but for my audience (which is essentially Latacora’s and HN’s), CT is fine.)
- adrianN 7y agoHook the alerting for expiring certificates into the library that is used for handling certificates, at least in debug builds.
- stubish 7y agoWe have an agent that pulls certs from an internal service and stores them on disk where apps can use them. We no longer manually install certificates. This solves discovery, and gives us alerts on services that have stopped refreshing their certs for any reason. The internal service is wired into lets encrypt and a commercial certificate provider. Setup is minimal, and after that completely automated.