Elektrine lite

← Feed

@Sibbo@sopuli.xyz

2026-09-19 11:12 UTC

Letsencrypt is under US jurisdiction. Is there a free-er alternative? I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

Replies (6)

  • @pHr34kY@lemmy.world 2026-09-19 11:30

    I don’t think anyone is gonna solve that problem until it’s actually a problem.

    Open ##4865056

  • @talkingpumpkin@lemmy.world 2026-09-19 15:33

    What risk are you trying to mitigate, specifically? If it’s the CA taking over your site, control over your CA specifically doesn’t really give any advantage to an attacker (they would have to hijack traffic and provide a new certificate - nobody will notice if the certificate is from a different CA). Note that your CA cannot decrypt the exchanges between your server and its clients.

    Open ##4869562

  • @possiblylinux127@lemmy.zip 2026-09-19 18:23

    Let’s encrypt is very transparent and has been designed to be auditable. What are you worried about exactly?

    Open ##4870369

  • @yesman@lemmy.world 2026-09-19 15:25

    Simi-related fun fact. The biggest contributor to TOR is the CIA. They funded it’s creation and are primarily responsible for maintaining it to this day. The CIA maintains TOR as a way for spies to pass information over the internet. They make it public because if only spies used TOR it would be trivial to catch them. So it’s in their interest that it be public and secure. It’s open source and security experts agree you can trust it.

    Open ##4871299

  • @pdl@social.tchncs.de 2026-09-19 12:02

    @Sibbo@sopuli.xyz I do not see any problem with Letsencrypt. Any CA which is widely trusted has to follow the same rules. This rules are set up by the CA Browser Forum. Which metadata does LE collect? My server's IP address, domain and subdomain, mail address. These are logged in the CT logs. Every CA has to log all certificates in a public CT log. Regardless which CA I choose, these data are public. There are not any critical data or metadata that LE can collect.

    Open ##4871848

  • @Fmstrat@lemmy.world 2026-09-21 02:15

    It is surprisingly easy to add a custom CA to phones and laptops. When I migrated to services using one with names like thisservice.lan I thought it would be a lot harder. I just have a generation script that makes a new cert and I throw it in NGINX.

    Open ##4878930