3 ms·
This reminds me of something I have been looking for for a long time. If you know any reasonable way to fix it please let me know! This "any CA can authenticat
by mkeedlinger 7y ago
This reminds me of something I have been looking for for a long time. If you know any reasonable way to fix it please let me know!
This "any CA can authenticate any domain" system is ridiculous. I manage my own CA, which is fine for my own self-hosted sites, but the issue is that it doesn't protect me from a cert made valid by some other CA.
Is there any way I can whitelist my own CA such that IT ALONE will work for my domains? (note: this is a me-only thing. Don't need anyone to be able to validate these domains).
PS, I've asked this question elsewhere [0] before. I did not find an adequate answer.
[0]: https://security.stackexchange.com/questions/211401/can-you-whitelist-a-single-ca-for-a-domain https://security.stackexchange.com/questions/211401/can-you-...
- zzzcpan 7y agoSee DNS CAA https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...
- mkeedlinger 7y agoThanks for the reply! This is very interesting, I will surely take a look. Only issue I see is that it seems to use DNS, and that's not exactly secure either. In my mind I am thinking of something that would be more theoretically secure from any remote attack (closer to a form of key-pinning maybe?)