3 ms·
That is how SSL is intended to work. You cannot have more than one SSL certificate for a given domain. That is an intentional design decision by the committee t
by MagicWishMonkey 13y ago
That is how SSL is intended to work. You cannot have more than one SSL certificate for a given domain. That is an intentional design decision by the committee that created the SSL RFC.
Does the door to your house support multiple types of keys? Or is it designed to work with a single, specifically machined key? Can you open your front door with your car key? Why not?
- pekk 13y agoWhy is one SSL key the only thing protecting these customers?
- MagicWishMonkey 13y agoBecause that is how SSL works. I don't understand your question. Your bank uses one SSL key as well. Google has one SSL key for their homepage. It is not possible for a top level domain to have more than one SSL certificate. Are you asking why SSL works the way it does? You'll have to talk to the people who wrote the RFC. SSL is what is used to protect communications between a client and the Lavabit endpoint. Once a request is inside the lavabit network other security measures are used. For example, each email message is signed using the account key for a given member, the account key is itself encrypted with the members password. The only way to decrypt a message is with the account key and the only way to decrypt the account key is with the member password. If you lose your password, your mail is gone forever. The feds had access to snowdens encrypted emails, but they had no way to decrypt them without his account password and the only way to do that is with snowdens personal password, which is why they wanted to sniff unencrypted traffic (to snag his password en route to the lavabit server). I've simplified a few things but this is a rough overview of how his system is designed.
- pekk 13y agoWhy is SSL the only thing protecting these customers? It's a really simple question and I think you are intentionally avoiding it and attacking a straw man.
- jtgeibel 13y agoThe entire second paragraph addresses the internal security beyond the SSL protection used in transit. But yes, in effect, SSL is the only thing protecting the user's password on the wire and this password is what is used to generate the master key for the encrypting the messages server side.
- tedunangst 13y agoYou cannot have more than one SSL certificate for a given domain. No, you cannot have more than one SSL cert for a given hostname (and port combo). You can assign a unique hostname to each user. The "oh, no, SNI doesn't work with IE 6" problem shouldn't have been a major problem for lavabit. Does the door to your house support multiple types of keys? The door to my apartment building is opened by one key. Everybody in the building has a copy. The door to my apartment is opened by a different key. The shared key is not the key that protects my stuff.