3 ms·
Full disclosure: I work for Smallstep. I love your point about being able to limit trust on hardened systems to your own CA. For servers, in many cases you don
by tashian 4y ago
Full disclosure: I work for Smallstep.
I love your point about being able to limit trust on hardened systems to your own CA. For servers, in many cases you don't need any CAs in the trust store, because a lot of services will only trust the roots you've explicitly configured (if you're using client authentication).
I've also noticed that Linux container distros generally ship with empty trust stores. So, a container distro can be a nice starting point for this.