3 ms·
If each user created their own key for a .ngrok.com subdomain, could ngrok then sign those, rather than giving out the private key? Would user agents consider t
by jarrett 12y ago
If each user created their own key for a .ngrok.com subdomain, could ngrok then sign those, rather than giving out the private key? Would user agents consider the subdomain's signed cert sufficient in that case? This is an odd little corner of SSL logic that I'm not as clear on.
- inconshreveable 12y agoSadly not. There is no delegation of authority for domains. If you are trusted to sign, you can sign anything. ngrok does see and ignore all of the decrypted traffic before it re-encrypts through the tunneled connection. This will change soon with SNI-based tunnels though.