Re: Using Commercial SSL/TLS Certificate for debian.org Site
Paul Wise <[email protected]>
| Newsgroups | gmane.linux.debian.devel.www |
|---|---|
| Organization | Debian |
| Message-ID | <[email protected]> |
On Wed, 2019-06-19 at 13:05 +0700, Bagas Sanjaya wrote: > It can be prevented by using wildcard certificates That is another terrible idea, if that one certificate is compromised then the attacker can impersonate any subdomain for the entire validity period. Moving towards individual certs and keys for each site with short validity periods with automatic renewal is a much better option. > Why did you say like that? Since there are no good reasons to do what you suggest. I won't be responding to this thread any longer. I request that you stop responding to this thread too. -- bye, pabs https://wiki.debian.org/PaulWise
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEYQsotVz8/kXqG1Y7MRa6Xp/6aaMFAl0J1WsACgkQMRa6Xp/6 aaNdSw/6A9qOWwZemZTRUeZhh8DvAaYIqzLZvwEJ61pcn16HwCDtA/O2pgVukfQ/ JXjK7vSiYmd0QA/3xhDaTT2AdfswZjEytWH5wE2X1GR0Bk4PlFg+b3ULScUkRE1K R45/Nwg3azgBzNFZX79wCfFUliqcsa2iKTqSShwl05q/ONpDZu7zpmhNlwHyICBM hUdw15wEPZXgJQC12Lj7LuZ7h4UvBN4Z1xkdOEJ00b+SGFjItbD2mTg2nTirMABh kJVdr0Vzt5jaUYApjLrwa2ACB7j8eBEGf+mNbTMR9ArU6M7APvQNoxDOrodSwFGk uvhojkmy/6BQBO9Iaz1lRQy6xAyeZByIfMYjREV5TbuUqSo8BEYQH9DC7n1Q45Do K7ULHGc06CIyrU4FgYsyGpIjZbOnbijjaF/Xm92VwLmVFCU3k/fhgbyrkuIChyPW 6NzoXK6KfiaNeYsZoAw7OJr0mFKs1lMAYy2hPPUVHQDsp9ayS2lD+T23PCyAlIT5 KfpQ32FFdXJbxZiSiV9nIkuxVQlbt8bipUGZ8iGtitwCDDi9c/acFKRsKrP12stg /MjFQIJi4uOTaHip70KXeIgTwUSDji/+T30giDepm+bY74q4LB5KsCC34hGMDBqf PNl1tCbY2qwhRYroZKJm3dDd+IS4Bo5UPjmHF3NpQkHEvQwqZoI= =DQcT -----END PGP SIGNATURE-----