4 ms·
You could use a self signed cert, as much as you like. We just don't have a good place to stash and validate them, so that when I visit your website (or my ban
by IcePic 2y ago
You could use a self signed cert, as much as you like.
We just don't have a good place to stash and validate them, so that when I visit your website (or my bank) I know which cert to expect. As soon as you invent this central place, you get the authority back again.
- zoezoezoezoe 2y agoWell, yes, but every browser and http tool is going to have alarms blaring shouting at the user that this site "isn't secure"--which isn't exactly true. A self-signed certificate is no different from one rubber stamped by a CA, the only difference is my self-signed cert is mine and mine alone, and the rubber stamped one I willingly rescinded my keys to a third party. What's funny (and sad) is we kinda do have a solution. In RFC 6698[1], using DNSSEC, we could use DNS-based Authentication of Named Entities (DANE) to have TLS without a CA, now, unfortunately, DANE is not supported literally anywhere anyone cares about, but we have it, no CA needed. As far as I see it, there is no reason to need a CA.
- tptacek 2y agoDANE is a certificate authority, just one baked into the DNS, where nobody has any recourse for misissuance. That's not the reason it failed in the marketplace (it failed because widespread crappy middleboxes maul DANE DNS requests, which means you can't deploy it in a mode without obvious downgrade attacks), but it's the reason nobody is putting much effort into coming up with a second iteration for it that might be workable --- after stapling failed, I think it's pretty much dead.