Re: Using Commercial SSL/TLS Certificate for debian.org Site

Paul Wise <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Organization Debian
Message-ID <[email protected]>
On Wed, 2019-06-19 at 13:05 +0700, Bagas Sanjaya wrote:

> It can be prevented by using wildcard certificates

That is another terrible idea, if that one certificate is compromised
then the attacker can impersonate any subdomain for the entire validity
period. Moving towards individual certs and keys for each site with
short validity periods with automatic renewal is a much better option.

> Why did you say like that?

Since there are no good reasons to do what you suggest.

I won't be responding to this thread any longer.
I request that you stop responding to this thread too.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEYQsotVz8/kXqG1Y7MRa6Xp/6aaMFAl0J1WsACgkQMRa6Xp/6
aaNdSw/6A9qOWwZemZTRUeZhh8DvAaYIqzLZvwEJ61pcn16HwCDtA/O2pgVukfQ/
JXjK7vSiYmd0QA/3xhDaTT2AdfswZjEytWH5wE2X1GR0Bk4PlFg+b3ULScUkRE1K
R45/Nwg3azgBzNFZX79wCfFUliqcsa2iKTqSShwl05q/ONpDZu7zpmhNlwHyICBM
hUdw15wEPZXgJQC12Lj7LuZ7h4UvBN4Z1xkdOEJ00b+SGFjItbD2mTg2nTirMABh
kJVdr0Vzt5jaUYApjLrwa2ACB7j8eBEGf+mNbTMR9ArU6M7APvQNoxDOrodSwFGk
uvhojkmy/6BQBO9Iaz1lRQy6xAyeZByIfMYjREV5TbuUqSo8BEYQH9DC7n1Q45Do
K7ULHGc06CIyrU4FgYsyGpIjZbOnbijjaF/Xm92VwLmVFCU3k/fhgbyrkuIChyPW
6NzoXK6KfiaNeYsZoAw7OJr0mFKs1lMAYy2hPPUVHQDsp9ayS2lD+T23PCyAlIT5
KfpQ32FFdXJbxZiSiV9nIkuxVQlbt8bipUGZ8iGtitwCDDi9c/acFKRsKrP12stg
/MjFQIJi4uOTaHip70KXeIgTwUSDji/+T30giDepm+bY74q4LB5KsCC34hGMDBqf
PNl1tCbY2qwhRYroZKJm3dDd+IS4Bo5UPjmHF3NpQkHEvQwqZoI=
=DQcT
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.