3 ms·
If you have servers in your intranet, but don’t have enough expertise to install a CA server and a CA certificate on end-users’ machines, maybe move to a cloud
by metafunctor 5y ago
If you have servers in your intranet, but don’t have enough expertise to install a CA server and a CA certificate on end-users’ machines, maybe move to a cloud based solution instead of hosting your own.
- qbasic_forever 5y agoThis is the hard truth. With a business and internal data, _especially_ customer data, you need to think of the liability if any of that data leaks or is accessed inappropriately. It will not look good in a lawsuit if a judges asks why data was so easily stolen and your response is that you didn't know some exploit was possible and didn't want to pay for experts to secure access to it. Managing certs, securing an internal network, etc. are just part of an ever evolving and changing security and threat landscape. You need to dedicate resources like time and money to constantly stay on top of it.
- dvdkon 5y agoMany vendors of internal tools don't have cloud offerings and even if they did, I wouldn't trust it considering their current security record. It would be a good CYA strategy, but that's about it.
- iso1631 5y agoYes, it's far more sensible to use something from a company that really understands security like Solarwinds rather than run your own nagios install. /s
- dec0dedab0de 5y agoSelf signed certs on an internal network are more secure than CA signed cert on a cloud.
- magicalist 5y ago> Self signed certs on an internal network are more secure than CA signed cert on a cloud. Not if your threat model is someone who already has access to the local network (which has no one managing it) snooping on traffic.
- dec0dedab0de 5y agoIt's still encrypted. They would have to man in the middle and hope that the user has not already accepted a cert. Exactly like most ssh servers.
- gregmac 5y agoThere are many use cases for accessing services local on the network that shouldn't need the 25-ton behemoth of a roll-your-own PKI ecosystem. I have a NAS, HomeAssistant, some random local-only IoT-type stuff, Plex, Pi-hole, and a handful of several other web applications running. Running my own PKI and having to manually distribute root cert to my non-domain PC let alone even think about how to install root certs on the various Android/iOS stuff I have: no thanks. I can think of several scenarios where a small business (with no IT) would have local servers but no dedicated IT (and where a full PKI infrastructure is a big burden): for example poor internet connectivity, or very high bandwidth costs.
- metafunctor 5y agoStrongly disagree. You can choose to run Pi-holes, Plex, and all that crap in your intranet and pretend you don’t need a CA. It’s not that hard to set up. Either learn how shit works or don’t do it. To be clear, I’m still talking about a scenario where you are running a company and process data for your customers. Hobbies are different.