Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Then you would just have two attack vectors; compromise either of the private keys and you can be the MITM.


You could use the same key and just submit multiple reqs to different CAs. This wouldn't be any worse than having one, and would be a way to have a "backup cert" in case a CA screws up.


Considering the private keys are probably stored in the same place, I wouldn't consider it an additional attack vector.


You can already MITM if you compromise any CA's private key.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: