4 ms·
I’m surprised by the number of requests to port 80, especially for requests to PKI certificate related domains. I assume there’s an element of chicken-and-egg s
by rhplus 4y ago
I’m surprised by the number of requests to port 80, especially for requests to PKI certificate related domains. I assume there’s an element of chicken-and-egg somewhere that means they can’t use TLS in certain cases. Can anyone offer insight into why this is OK and not subject to MITM attacks on the certificate validation/supply chain?
- josteink 4y agoX509 cert retrievals is predominantly done over HTTP, because otherwise you’d need X509 to implement X509. It may sound “insecure”, but if you can’t trust X509 without HTTPS, you effectively can’t trust either X509 or HTTPS. This is why we have layers in software. We trust X509 because of fundamental math. Therefore we trust HTTPS built on X509. Therefore we trust systems built on HTTPS. Everything is perfectly fine.