4 ms·
Wildcard certs are generally discouraged in secure environments due to a single cert being compromised can lead to a variety of compromised services -- or an at
by nullindividual 2y ago
Wildcard certs are generally discouraged in secure environments due to a single cert being compromised can lead to a variety of compromised services -- or an attacker adding their own subdomain and 'valid' service.
- metadat 2y agoAgreed, as a rule of thumb. Yet when it's, say, a certificate for the HomeAssistant service at my personal residence, avoiding the subdomain being published to the transparency log is advantageous from a both a privacy and security perspective. Naturally, best practices depend on the use-case and context.
- jsheard 2y agoIf you're relying entirely on LetsEncrypt for a service which uses hundreds or thousands of subdomains (e.g. one per user) then you practically have to use a wildcard too, because generating tons of individual certs for the same top level domain will very quickly run into LEs rate limits.
- BadBadJellyBean 2y agoYou can request a higher rate limit: https://isrg.formstack.com/forms/rate_limit_adjustment_request https://isrg.formstack.com/forms/rate_limit_adjustment_reque...
- stop50 2y agoFor really secure environments you use your own hardware backed ca.
- 8372049 2y agoOn an airgapped network (if possible)
- dddw 2y agoDon't forget to update that hardware then. And to inform whoever inherits the infra to update te ca after 10 years.
- nullindividual 2y agoThere are levels of security, or more like levels of risk one can take on. For the home environment, I'd agree that for most wildcards aren't much of a risk. For an SMB, LE with individual certs may be ok. For a multinational bank or similar, yes absolutely HSM on an airgapped CA seems like a better approach.