4 ms·
This of course, only works for your own internal use. I feel this disclaimer needs to be called out explicitly. If you're trying to do something that will be t
by RandomBK 3y ago
This of course, only works for your own internal use. I feel this disclaimer needs to be called out explicitly.
If you're trying to do something that will be trusted by the global internet, you'll need to use an official CA, ergo the complaints of DNSSEC being too 'centralized'.
- IcePic 3y agoThen again, what the "global CAs" are doing is not wholly different in a technical level than what a company with their own internal CA does, except that I hope the global CAs take security very very seriously, and they pass an expensive audit. In the end, it is just some company or organisation that creates a root CA cert and intermediaries, and then jump through hoops to make browsers and OS cert stores add their certs. Not saying it is easy, just that the technical parts are rather similar, the rest being a cumbersome way to prove you are trustworthy by showing off your processes and fences around the signing boxes.
- RandomBK 3y agoIn the case of DNSSEC, the ultimate 'root key' is handled quite carefully and is interesting to read up on. https://www.iana.org/dnssec/files https://www.iana.org/dnssec/files https://www.cloudflare.com/dns/dnssec/root-signing-ceremony/ https://www.cloudflare.com/dns/dnssec/root-signing-ceremony/
- detourdog 3y agoOne can distribute self signed ssl certificates. Not using a CA is more secure for the group relying on the certificates to maintain encryption.