4 ms·
Then you would just have two attack vectors; compromise either of the private keys and you can be the MITM.
by raylu 14y ago
Then you would just have two attack vectors; compromise either of the private keys and you can be the MITM.
- WatchDog 14y agoConsidering the private keys are probably stored in the same place, I wouldn't consider it an additional attack vector.
- rdl 14y agoYou could use the same key and just submit multiple reqs to different CAs. This wouldn't be any worse than having one, and would be a way to have a "backup cert" in case a CA screws up.
- dspeyer 14y agoYou can already MITM if you compromise any CA's private key.