3 ms·
Yeah, the argument apparently doesn't really grok how certificates are issued and why the changes exist. Manual long term keys are frowned upon due to potentia
by ownagefool 1y ago
Yeah, the argument apparently doesn't really grok how certificates are issued and why the changes exist.
Manual long term keys are frowned upon due to potential keyleaks, such as heartbleed, or admin misuse, such as copy of keys on lots of devices when you were signing that 10 year key.
Automated and short lived keys are the solutions to these problems and they're pretty hard to argue against, especially as the key never leaves the server, so the security concerns are invalid.
That's not to say you can't levy valid criticism. I'm not sure if the author is entirely serious either though.
p.s. Certbot and Cert-manager are probably fine, but they're also fairly interesting attack vectors