4 ms·
If you want that level of security, your only solution is to own all your servers and have very strong physical security. The problem is that most web sites can
by ivanr 13y ago
If you want that level of security, your only solution is to own all your servers and have very strong physical security. The problem is that most web sites cannot justify the expense.
If you follow all the recommendations from the guide -- which is not that hard, in my opinion -- your (TLS) security will be among, say, 0.1% of the sites out there, or better.
Going back to the key protection: for the rest of us, the best you can do is always use a password with your key. That won't protect it on the web server, but it will protect it when you back it up independently.
Then, find a CA that allows unlimited key/certificate regeneration and rotate your private key (and revoke the previous certificate) every month, and every time your staff changes.
- taway2012 13y agoThe TaoBao version of nginx has a patch to send the private key through the network to the server. IIRC. In that case, it won't be lying around in plaintext on your server's disk. I will edit this post with a link if I can find it again. I run a small number of servers, so I've password-protected my private keys.
- ivanr 13y agoThat's interesting, but I don't think it raises the bar a lot. Private keys are still kept in process memory, from where they can be easily extracted by the attacker who can attach to the process. A great innovation would be to have web server fork a special process that will only handle private keys. That other process would be running under a different username. Bonus points if a separate process can be deployed for each key. (It's possible to achieve a similar effect by running decryption in a separate proxy layer.)
- deleted 13y ago[deleted]
- taway2012 13y agoMy two cents is that requiring the ability to snoop on a running process is a significant extra hurdle compared to simply reading the filesystem. Especially for virtual machines which almost everybody is running on these days. An attacker can simply read the disk from under the OS. Although I can understand why you might think it's not significant enough. I do agree that storing private keys in a separate user's process can help with security.
- taway2012 13y agoReplying to myself since I can't edit my reply now. This is the link to the TaoBao Tengine doc describing the feature: http://tengine.taobao.org/document/http_ssl.html http://tengine.taobao.org/document/http_ssl.html My memory was faulty: they have a way to get the passphrase, not the key itself. But wrt security, both are equivalent.