3 ms·
[I wrote that document.] With wildcard certificates, the main danger is that multiple groups with the organization will have access to the same private keys. Th
by ivanr 13y ago
[I wrote that document.] With wildcard certificates, the main danger is that multiple groups with the organization will have access to the same private keys. The larger the group the worse the security gets: the chances of the private key leaking are higher, and the people from different groups effectively gain undetectable MITM capabilities against all other systems. The same goes for the intruder, who will gain access to everything after compromising a single system. From that perspective, it's much better to use separate certificates and keys, and compartmentalize everything.
Then, you are supposed to rotate your keys when someone leaves, or if there is a compromise. Revoking a shared private key is nearly impossible if it is used in multiple systems. People get really afraid of breaking stuff, and if they do, it takes them ages to fix everything.