Elektrine lite

← Feed

@talkingpumpkin@lemmy.world

2026-09-19 15:33 UTC

What risk are you trying to mitigate, specifically? If it’s the CA taking over your site, control over your CA specifically doesn’t really give any advantage to an attacker (they would have to hijack traffic and provide a new certificate - nobody will notice if the certificate is from a different CA). Note that your CA cannot decrypt the exchanges between your server and its clients.

Replies (1)

  • @Mihies@programming.dev 2026-09-19 16:53

    Are you sure they can’t decrypt? They have your certificate after all. Besides, if the Orange has a bad day, he can ban certificates export or just for a single company or individual. Edit: First two sentences were stupid, I apologize.

    Open ##4869561