←back to thread

238 points edent | 1 comments | | HN request time: 0.21s | source
Show context
thrower123 ◴[] No.29809874[source]
Is it that hard to setup an internal CA? I have no idea what I'm doing, and I managed one for years until we moved offices and ditched our LAN.
replies(2): >>29810066 #>>29812549 #
1. midasuni ◴[] No.29812549[source]
That should worry the hell out of you.

If you could install CAs only for a certain domain (default to the name constraints but actually set in the browser/Os) that would be fine, but installing a CA gives anyone with access to that CA the ability to make pretty much any valid cert, and your potential lack of security raises flags