4 ms·
It does not. Anchor never see sees your private keys for certificates. We hold an ACME account key on your behalf with the CA, but we cannot use it impersonat
by benburkert 1y ago
It does not.
Anchor never see sees your private keys for certificates.
We hold an ACME account key on your behalf with the CA, but we cannot use it impersonate your domain or decrypt traffic.
We have a more technical overview of how this works in our docs: https://anchor.dev/docs/public-certs/acme-relay https://anchor.dev/docs/public-certs/acme-relay
- masfuerte 1y agoIf users delegate their DNS to you, what's stopping you issuing a certificate to yourself for their site?
- nbadg 1y agoCertificate transparency logs are likely the only realistic way, but you could make the same argument against your DNS provider. Trust has to start somewhere. Whether or not something like this makes sense to you is probably a question of your personal threat model.
- weddpros 1y agoSeeing how people are worried about third parties issuing certificates, I encourage using a tool to monitor CT Logs. It really makes the fog of war disappear around your certificates. https://crt.sh https://crt.sh for point in time checks, https://sslboard.com https://sslboard.com for comprehensive oversight (disclosure: I'm the founder)
- benburkert 1y agoWe theoretically could, but those certificates would show up in CT logs. (For quick & easy monitoring, you can get an RSS feed for your domain on https://crt.sh/ https://crt.sh/, but it's not the most reliable service.) It would be a reputation killer if we did that, just like it would be for your DNS provider or ISP.
- masfuerte 1y agoRight, but if you want people to trust you, you need to be open about what people are trusting you with. Your original answer seemed obfuscatory.
- benburkert 1y agoSorry, not trying to obfuscate anything, hopefully this clarifies: users trust us to hold their ACME account key and we only ask for DNS records prefixed with `_acme-challenge.` to be CNAME delegated. With this we could issue or revoke a new certificate, but we couldn't impersonate them because we don't control the rest of their DNS.
- dogleash 1y ago> we couldn't impersonate them because we don't control the rest of their DNS. If that were true, nobody would need signed certificates in the first place.
- hannob 1y ago> We hold an ACME account key on your behalf with the CA, but we cannot use it impersonate your domain or decrypt traffic. That makes no sense whatsoever. If you have an ACME account key for my domain, of course you can use it to impersonate my domain. You just need to create another certificate. (Which I could detect, but if I know how to do that, I'm probably not going to need your service anyway.)