3 ms·
Hi Jordan, We are essentially acting as an easy-to-use, "client focused", Certificate Authority for SSH and X.509. So, in the simplest threat model, yes, if o
by pquerna 11y ago
Hi Jordan,
We are essentially acting as an easy-to-use, "client focused", Certificate Authority for SSH and X.509.
So, in the simplest threat model, yes, if our hosted SaaS version is compromised, your infrastructure is threatened. We believe many of our larger customers will adopt an "on premise" style deployment for this and other reasons -- doing this on premise is not very different than their threat model for a central LDAP server or other identity provider many have today.
Having said that, we are incorporating all the best practices you would see in a CA for other purposes, and believe for some segments this is a viable and major improvement over their current security practices.