• 8 Posts
  • 19 Comments
Joined 1 year ago
cake
Cake day: June 13th, 2023

help-circle



















  • Please feel free to explain your stance more, also I’m not an expert. But that seems like a potentially dangerous statement. Certificates are a multifacted issue which cannot be covered by “Self signed certs are more secure”. Even in an environment you are fully managing intermediate and leaflet certificates, you want the root issued by a public CA. Ideally an EV CA. If the infrastructure is fully internal, there are still advantages to using an external CA (like for getting a root cert) unless you are able to securely generate, store, revoke, cycle, and manage the root certificates. As for trusting certificate chains, again multifaceted, but they fix a lot more problems than they cause and increase security posture. Having one off pairs per service at any but the smallest scale is security nightmare fuel.