3 ms·
That's great! Thanks for open sourcing it. I really don't think there's much value though if it's not self-hosted -- it just adds another point of failure to
by timmclean 12y ago
That's great! Thanks for open sourcing it. I really don't think there's much value though if it's not self-hosted -- it just adds another point of failure to the CA system.
Edit: what if this were built into Firefox? Could the certificate manager accommodate some UI improvements and an export feature?
- Lukasa 12y agoRe building into Firefox: It absolutely could, and I'd love it if someone went ahead and did it. That would be a big coup for Mozilla and it simply can't be that hard to do. Hell, the Chrome guys could do it, mkcert is build on one of Adam Langley's tools anyway. As for self-hosting, I think anyone who wants to deploy mkcert in anger should self-host, and I believe I've made it trivial to do that. There are some steps I can still take to improve this: I want to pin Mozilla's cert in the client so that it can't be MITM'd, for example.