3 ms·
I think OP was envisaging the attack being done by the person whose root CA private key it is.
by karatinversion 3y ago
I think OP was envisaging the attack being done by the person whose root CA private key it is.
- worik 3y ago> I think OP was envisaging the attack being done by the person whose root CA private key it is. Still very convoluted. I cannot see the problem, beyond some very special cases.
- 8organicbits 3y agoThere's two parts. The first is getting access to the private CA's private key. This is easy for insiders who already have access, but challenging for external attackers. The second is performing a MITM attack. You need to establish an in-the-middle network position and then craft certs for the sites you want to intercept. Insiders may already have the needed network position. Outsiders may find this challenging. Crafting a bogus certificate is trivial with a private CA.