3 ms·
When pressed, they admitted it was just "gut feeling". The team audited a couple ACME clients and couldn't find anything to justify not automating.
by revvx 7y ago
When pressed, they admitted it was just "gut feeling". The team audited a couple ACME clients and couldn't find anything to justify not automating.
- dingaling 7y agoHaving a root process with write-privileges to /etc on production machines and also able to communicate over the Internet definitely is a security risk. To mitigate that you end-up building a series of privilege-restricted jobs flowing from the DMZ back into the internal network. And maintaining that might be more complicated than just manually renewing, depending upon the processes and architecture of the company.
- Whitestrake 7y agoWhy would a process need to run as root or have write privileges to /etc in order to automate LetsEncrypt renewals? I run Caddy (which uses acme-go/lego as its ACME provider) as a non-root user with no access to /etc at all. It seems to be running fine.
- tedunangst 7y agoDepends on setup, but frequently private keys are inaccessible to the web server worker process. (Which starts as root, loads keys, drops privs, etc.)
- tialaramex 7y agoMost popular ACME (Let's Encrypt) clients allow you to provide a CSR instead of generating the keys themselves. That means a bunch more work for you, but if you're worried about this, that's what you should do. Have your safe (even manual if you insist) process make keys, make CSRs for the keys, and put those somewhere readable. The ACME client will hand them over to the CA saying "I want certs corresponding to these CSRs" without needing access to your TLS private keys at all.
- rocqua 7y agoThat does mean you aren't automatically rotating keys anymore.
- revvx 7y agoIf you trust your automation, you put private key rotation into it. If you don't trust it your automation, you rotate the keys manually, as you would normally. There are no valid reasons to throw the baby away with the bathwater.
- rocqua 7y agoUsing http renewal requires listening on port 80 which, by default, requires root.
- Whitestrake 7y agoThis is technically true, but contextually lacking. acme-go/lego doesn't use HTTP validation unless you disable just about every other form of validation first. TLS-ALPN validation is much more likely, so port 443. That said, it is very easy to allow software to bind to privileged ports without providing it root access; this has been solved for a very, very long time.
- deleted 7y ago[deleted]
- revvx 7y agoYou can just use the web server that is already running on the machine. You (normally) don't want downtime in your website, so you just let your regular webserver serve the acme challenge instead of stopping it.