Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?

<- View Parent
pdl@social.tchncs.de ⁨23⁩ ⁨hours⁩ ago

@flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA.

original
Sort:hotnewtop