5 ms·
Isn’t the hash ( before the . Onion) is the public key ? So technically we don’t need a cert for onion
by SalimoS 6y ago
Isn’t the hash ( before the . Onion) is the public key ?
So technically we don’t need a cert for onion
- milkey_mouse 6y agoYou're correct, but I recall a Tor dev saying at one point that HTTPS for .onion wasn't completely useless, I think in that more secure settings (CSP, etc.) apply to pages loaded with HTTPS.
- jeremiahlee 6y agoThe Tor Project discussed the advantage a little in this blog post ("Part four: what do we think about an https cert for a .onion address?"): https://blog.torproject.org/facebook-hidden-services-and-https-certs https://blog.torproject.org/facebook-hidden-services-and-htt...
- surround 6y agoSome onion websites use the certificate as an anti-phishing measure. Since onion domains are hard to remember, a certificate can verify that you are, indeed, connected to e.g. Facebook’s servers and not a phishing website.
- bawolff 6y agoPresumably worked a lot better when EV certs got the fancy UI
- lights0123 6y agoThat's EV though, and it looks like DigiCert is the only one that does it for .onion: https://crt.sh/?Identity=%25.onion https://crt.sh/?Identity=%25.onion They do offer ACME though: https://docs.digicert.com/certificate-tools/Certificate-lifecycle-automation-index/acme-user-guide/ https://docs.digicert.com/certificate-tools/Certificate-life...