5 ms·
Having to communicate with outside is kinda overkill if you just want to have container A talking to container B. But the solution is internal CA, not self sig
by adql 3y ago
Having to communicate with outside is kinda overkill if you just want to have container A talking to container B.
But the solution is internal CA, not self signed certs that defeat near-entire point of encrypting communication.
- flerchin 3y agoYes an internal CA is better than a self-signed-cert. However, I've come across, quite often, where an internal CA causes problems that are only at that enterprise. Using the established public CAs is generally more resilient, and there's _no reason to not_.
- czx4f4bd 3y agoUnfortunately, enterprises are intensely risk averse. I worked at a place where we could only generate proper certs by manually submitting a ticket to IT and waiting probably days to get it back, giving us zero hope of applying meaningful automation. Getting certs from a proper CA was absolutely forbidden, despite our lobbying, so in a lot of cases self-signed certs were the only option if we wanted to automate.
- geraldwhen 3y agoWhere I work it’s months, and fights, and maybe even several meetings. And that’s only if you fill out the correct form the exact right way. Any slight deviation and your ticket is closed weeks after you opened it with the field you got wrong.
- mirekrusin 3y agoLook at the bright side. If things like that worked we wouldn’t have startups.
- c00lio 3y agoThere are tons of reasons to not use an external CA. First, cost. Any CA that issues unlimited certificates will charge tons of money. Free CAs like letsencrypt do have rate limits that we would frequently hit with autoscaling environments, CI jobs, and such. Also, CAs require the use of certificate transparency logs. Which will expose your internal infrastructure data to the public. It will, by exposing autoscaling data, also expose financial data (at least in hints), e.g. by showing that last christmas, your scaling peak was far higher. And external CAs are a security risk because you need to provide firewall exceptions and/or transfer mechanisms for certificates into your internal infrastructure that you would usually want to isolate. Lastly, an external CA is an availability risk. Should your external CA be unreachable for some reason, you might not be able to run any CI jobs or auto-scale-up your infra.
- deleted 3y ago[deleted]
- flerchin 3y agoACM is effectively free. Cost is not an issue. None of your data is exposed. This is all FUD.
- madeofpalk 3y agoCertificate Transparency Logs don't exist?
- omniglottal 3y agoIt you are not personally aware of the basis behind a security posture, please avoid denouncing it as FUD. Yout own ignorance, uncertainty, or doubt does not suffice to replace the informed advice of a professional.
- gruturo 3y agoI'm sorry but this is simply not true. Certificate Transparency logs ARE (meta?)data which would be exposed. If the certificates were meant to be reached externally, you wouldn't indeed care at all - but if they're for internal flows (e.g. App server to DB, 2 steps behind a balancer and a set of web frontends) you are indeed publishing stuff you would have rather kept private. Before this (d)evolves into a zero trust, security-by-obscurity discussion - some auditors won't certify you in some edge cases related to this, and you may be operating in a regulated sector where such a certification is necessary. Just because it doesn't impact your use case, doesn't mean this is the case for someone else.
- diarrhea 3y ago- Certificate Transparency logs leak internal domain names, therefore potentially internal infrastructure or product still in stealth mode - HTTPS challenge requires opening the network to the entire internet - DNS challenge requires API access to the DNS provider. The DNS entries are the keys to the castle (MX mainly). Some names ever operators don’t offer sensible API access (none at all, or poor scoping (single token with global admin access))
- iso1631 3y agoI have one supplier that uses letsencrypt to generate a wildcard certificate, then distributes it as part of a software update to thousands of machines in hundreds of companies across the world. The exact same certificate and key. But it gets rid of the red X in a browser so tick It's less secure than a self signed cert. OK you can't just sniff traffic and decode it thanks to Elliptic Curve, despite having the cert+key, but you can MITM just as much, and not throw an error. With a self-signed if someone has accepted and cached the self-signed cert you can't MITM them without throwing an error.