The transparency logs would mean that any rouge certificates created would leave a paper trail not to mention there is nothing stopping them from issuing a certificate for any domain of there choosing
Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
flandish@lemmy.world 23 hours agouncle sam. audit away. until sam says “give me the keys” and then sam has the keys
possiblylinux127@lemmy.zip 20 hours ago
pdl@social.tchncs.de 23 hours ago
@flandish @possiblylinux127 Letsencrypt just has the public keys, no private keys. If Letsencrypt gives my public keys to sam, it does not matter, because public keys are public. My private key is under my administration only.
flandish@lemmy.world 22 hours ago
and the backdoor?
pdl@social.tchncs.de 21 hours ago
@flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA.
pdl@social.tchncs.de 21 hours ago
@flandish If US authorities want to fake my server, they can use any CA, regardless which CA I originally used.
Of course, US authorities can force Letsencrypt to revoke my certificates and block any renewing. This is very unlikely to happen. If it happens, I have to change my CA. There would be a downtime for my private services, but there is no data corruption or data loss on my servers.