6 ms·
What about having your own (self-signed) CA? You sign your own certificates and import that CA on your computer. Would this effectively prevent a man in the mid
by akirk 14y ago
What about having your own (self-signed) CA? You sign your own certificates and import that CA on your computer. Would this effectively prevent a man in the middle attack?
- Zash 14y agoGood luck getting Google to trust your CA ;)
- akirk 14y agoSorry, my question was not actually meant to be about this Google situation but about the general approach to using your own CA instead of self-signed certificates.
- omh 14y agoAs long as you don't need your services to be used by third parties then a private CA is a good option, and in some ways more secure than traditional root CAs.
- Nursie 14y agoSo long as you can find a secure way to get your CA cert onto whatever systems need to verify your server certs, it can be a very good thing. The main advantage of this over public infrastructure is that you don't have to trust the authorities, some of whom have in the past been caught handing out dodgy certificates or been compromised. For a set of private systems that don't need to interface with the public internet and unknown clients, I would go so far as to recommend it. You must keep your master keys safe of course!
- RyanZAG 14y agoIt will prevent it as long as the client has your CA's public certificate embedded. Browsers/OS embed all of the normal CA's certs so that you know any cert signed by a regular CA is authentic. However, regular CAs are not incredibly trustworthy and are a security problem... (Regular CAs can be attacked with fairly easily with social attacks, and some CAs can even be bribed or hacked.) Giving Google your CA or your public mail cert are effectively the same thing in theory, as long as Google only uses your CA cert to authenticate your own servers and not anybody elses. In practice, current CA management software in most OSes is (imho) faulty, and will allow any CA in the chain to authenticate any cert. This probably needs to be fixed at some point... So until then, there is no way Google is going to accept your CA, but they SHOULD change their systems to accept a specific public cert for a mailserver for POP3 fetching.
- Nursie 14y agoYou would hope the smart minds at google could come up with a management system for this fairly easily, though I guess it does add complexity when you're dealing with potentially millions of these servers and millions of trusted roots.
- mseebach 14y agoSelf-signed in this context basically means "signed by something else than a trusted CA", not the strict meaning of signing a certificate by itself. There are two elements to public key crypto: The encryption itself (which is perfectly fine on a self-signed cert) and certificate distribution (for which the best current solution are the globally trusted CAs). If you can somehow guarantee that your attacker can only listen to your data, not inject himself as a MITM, self signed is perfectly adequate to protect yourself. The catch is that providing this guarantee is very difficult.