3 ms·
So, the 2-year rule is a guess-work. Is that the conclusion I should make? There should be a way to remove public CA:s if they are as worthless as they seems to
by AtNightWeCode 4y ago
So, the 2-year rule is a guess-work. Is that the conclusion I should make? There should be a way to remove public CA:s if they are as worthless as they seems to be. I trust my local vaults (which I have to trust anyway) more than a public CA. It seems a bit stupid for two intelligent parties to trust a common moron more than each-others.
- efortis 4y agoYes, but it's for more than that. For instance, think of design issues with the algorithms. At any rate, 2 years is way too long, change them at least monthly. === BTW, I think I see your scenario, are you using TLS for connecting to a database between servers you own? If that's your case, use symmetric encryption instead. e.g., with spiped [1] or some other tunnel. [1] http://www.tarsnap.com/spiped.html http://www.tarsnap.com/spiped.html
- AtNightWeCode 4y agoPrivately you can always rotate at any speed or do whatever. Typically fully automated. The Q is about public certs. I never seen a fully automated cert upgrade outside fully manged services.
- efortis 4y agoIt's doable with certbot[1] or using other scripts. But I don't recommend it for the reasons explained in the blog post[2] I mentioned in the first comment: [1] https://github.com/certbot/certbot https://github.com/certbot/certbot [2] https://blog.uidrafter.com/isolated-tls-certificate-creation https://blog.uidrafter.com/isolated-tls-certificate-creation
- AtNightWeCode 4y agoThanks for your input. I appreciate it. Apparently, a bit annoyed yesterday. Had to handle certs in my spare time. :) I agree about certbot. Worked with a setup that had it in a container in a cluster. Not very secure.