4 ms·
Insane that they're dropping client certificates for authentication. Reading the linked post, it's because Google wants them to be separate PKIs and forced the
by noirscape 10mo ago
Insane that they're dropping client certificates for authentication. Reading the linked post, it's because Google wants them to be separate PKIs and forced the change in their root program.
They aren't used much, but they are a neat solution. Google forcing this change just means there's even more overhead when updating certs in a larger project.
- ggm 10mo agoThe certification serves different purposes. It might feel like a symmetric arrangement but it isn't. On the whole i think implementing this split is sensible. I might add I've changed my mind a bit on this.
- cyberax 10mo agoIt's a good change. I've seen at least one company that had misconfigured mTLS to accept any client certificate signed by a trusted CA, rather than just by the internal corporate CA.
- LtWorf 10mo agoShould we remove anything that was at some point misconfigured somewhere?
- zzo38computer 10mo agoI (partially) agree that it is a good change, but for a different reason. For security purposes, the certificates should include only the permissions that are required (although maybe they ought to allow you to have certificates that include both if you have a use for it (which as I have mentioned, you usually should not need because you will probably want to use different certificates instead), but unfortunately they do not allow that).
- throwaway81523 10mo agoIs that a temporary situation? Is it that big a deal to implement a separate set of roots for client certs? Or do you mean that the entire infrastructure is supposed to be duplicated?
- bigbuppo 10mo agoGoogle doesn't understand how the real world works. Big shock.
- grayhatter 10mo agoThey do understand, this is moat digging.
- zzo38computer 10mo agoI think client certificates are a good idea, although it is usually more useful to use different certificates than those for the domain names, I think. (I still think CA/Browser Forum is not very good, despite that; however, I still want to mention my point.)