←back to thread

238 points edent | 1 comments | | HN request time: 0.219s | source
Show context
tomc1985 ◴[] No.29810658[source]
Why not just be your own signing authority for internal domains? You can propagate your toplevel public cert with most enterprise network provisioning tools.
replies(2): >>29810766 #>>29811122 #
1. reincarnate0x14 ◴[] No.29811122[source]
Not only is running your own CA a pain, there is also minimal support for restricting CA scope validity, so anyone that needs to communicate with you effectively ends up trusting your CA for anything and everything. For most anyone except your own trusting partners or coworkers that's a complete non-starter.