4 ms·
Itʼs so strange that they didnʼt manage to set up a proper certificate for an HTTPS proxy project website: https://www.ssllabs.com/ssltest/analyze.html?d=www.to
by manwithaplan 5y ago
Itʼs so strange that they didnʼt manage to set up a proper certificate for an HTTPS proxy project website: https://www.ssllabs.com/ssltest/analyze.html?d=www.tofuproxy.stargrave.org&s=91.211.5.21 https://www.ssllabs.com/ssltest/analyze.html?d=www.tofuproxy...
Edit: I guess theyʼre philosophically opposed to PKI, and are promoting instead certificate pinning, Web-of-Trust:
http://www.stargrave.org/Harmful.html http://www.stargrave.org/Harmful.html
This makes me wonder if itʼs possible to get `Letʼs Encrypt` to cross-sign an HTTPS certificate issued by another CA?
- stargrave 5y agohttp://www.stargrave.org/WhyNotLE.html http://www.stargrave.org/WhyNotLE.html
- pabs3 5y agoIIRC signing by multiple CAs isn't possible, so you would have to extend TLS or X.509 or both.
- redleader55 5y agoIt is currently possible to present multiple certificates when the connection is initiated using TLS. These certs are usually a chain - from CA to intermediate CA and then the final cert, but it should be possible to present certificates from different chains. The question is how the clients would be able to handle this.
- redleader55 5y agoIt's naive to think you can scale the web we have today on web of trust. If you didn't know, Google Chrome ignores to a large extent the whole certificate revocation infrastructure because it's slow and it has privacy issues[0]. How would things work if you would check every single web request you make against the web of trust? Your peers would know every site you visit, or worse, a notary for your trust would know every site you visit. PKI works because the check is local and based on time and cryptographic signatures. [0] https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol#Browser_support https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
- pabs3 5y agoOCSP stapling solves the privacy issues IIRC.