3 ms·
Make your own CA, install on each computer, install certificates, voila.
by rcdwealth 6y ago
Make your own CA, install on each computer, install certificates, voila.
- tsimionescu 6y agoRepeat every 3 months or whenever the root certs expire.
- jodrellblank 6y ago3 months? I must have updated FireFox / Discord / VS Code /etc. about a hundred times in last 3 months. Plenty for them to add renewed SSL whatevers inside one of the updates.
- Wowfunhappy 6y ago> 3 months? I must have updated FireFox / Discord / VS Code /etc. I think this state of affairs is nuts. With the exception of Firefox, because web browsers have an inordinate number of security issues to contend with.
- throwaway53453 6y agoAnd other programs don't?
- Wowfunhappy 6y agoAn instant messaging client shouldn’t be executing arbitrary remote code, no.
- throwaway53453 6y agoIt's not really possible to prevent that. E.g. a well crafted image can easily trigger an RCE on some older versions of Android: https://nakedsecurity.sophos.com/2019/02/08/android-vulnerabilities-open-pie-to-booby-trapped-image-attacks/ https://nakedsecurity.sophos.com/2019/02/08/android-vulnerab... Issues like this exist at all layers of the stack, so anything touching the internet needs regular security patches.
- Wowfunhappy 6y agoI agree completely. But, I also think that in most cases, if a simplistic piece of software like an IM app needs a security patch every three months, regularly, it's a sign the attack surface is too large.
- upofadown 6y agoWhy would the certs you create for this purpose be made to expire?
- tim-- 6y agoIt needs to expire before 397 days, because otherwise the CA will not be valid, even if it is marked as trusted. https://www.zdnet.com/article/google-wants-to-reduce-lifespan-for-https-certificates-to-one-year/ https://www.zdnet.com/article/google-wants-to-reduce-lifespa... edit: a word
- achew22 6y agoThe article you linked to is kind of confused and I'm not sure I blame them. This stuff is really complex! According to the proposal[0], leaf certificates are prohibited from being signed with a validity window of more than 397 days by a CA/B[1] compliant Certificate authority. This is very VERY different from the cert not being valid. It means that a CA could absolutely make you a certificate that violated these rules. If a CA signed a certificate with a longer window, they would risk having their root CA removed from the CA/B trust store which would make their root certificate pretty much worthless. To validate this, you can look at the CA certificates that Google has[2] that are set to expire in 2036 (scroll down to "Download CA certificates" and expand the "Root CAs" section) several of which have been issued since that CA/B governance change. As of right now, as far as I know, Chrome will continue to trust certificates that are signed with a larger window. I've not heard anything about browsers enforcing validity windows or anything like that, but would be delighted to find out the ways that I'm wrong if you can point me to a link. Further, your home made root certificate will almost certainly not be accepted by CA/B into their trust store (and it sounds like you wouldn't want that) which means you're not bound by their governance. Feel free to issue yourself a certificate that lasts 1000 years and certifies that you're made out of marshmallows or whatever you want. As long as you install the public part of the CA into your devices it'll work great and your phone/laptop/whatever will be 100% sure you're made out of puffed sugar. I guess I have to disclose that I'm an xoogler who worked on certificate issuance infrastructure and that this is my opinion, that my opinons are bad and I should feel bad :zoidberg:. [0] https://github.com/cabforum/servercert/pull/138/commits/2b06f7839daa45f685e37c51d74e255ef4ff9d75#diff-f7368cf58de0586cb0ad80e242205ab3272314af71f4115b99187f49521da529R1341 https://github.com/cabforum/servercert/pull/138/commits/2b06... [1] https://en.wikipedia.org/wiki/CA/Browser_Forum https://en.wikipedia.org/wiki/CA/Browser_Forum [2] https://pki.goog/repository/ https://pki.goog/repository/
- Leherenn 6y agoTelling your clients to install your certificate in their computer/browser store is not very practical. And they will need to do that regularly.
- 10000truths 6y agoIt shouldn’t be practical, that’s by design. Imagine if every captive portal had you install their root certificate to access the WiFi, with just the click of a button.
- midasuni 6y agoNot regularly, my root is 10 years long.