per-entity - Re: [Per-Entity] TLS private keys and CDNs
Subject: Per-Entity Metadata Working Group
List archive
- From: Nick Roy <>
- To: <>
- Subject: Re: [Per-Entity] TLS private keys and CDNs
- Date: Wed, 21 Sep 2016 10:39:57 -0600
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:C6V7OxA+FlHBGTt2ql/uUyQJP3N1i/DPJgcQr6AfoPdwSP39psbcNUDSrc9gkEXOFd2Crakb26yL6Ou5BCQp2tWojjMrSNR0TRgLiMEbzUQLIfWuLgnFFsPsdDEwB89YVVVorDmROElRH9viNRWJ+iXhpW1aJhKqYRJ4PKH4HJLTk9Wf1ua5/JjWZAMOgyCyN+BcNhKz+CPQvcpeu4xzYvI30BzYinpOZ+lMw250fxSekwuqtZT4x4Jq7ykF46FpzMVHS6ivJ6k=
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
I actually like this better than them generating the key signing
requests themselves. This lets us potentially share the same
hostname across CDNs and front it with our own DNS strategy. Not
writing to disk isn't a mitigation since key-in-memory is similarly
risky, the only real mitigation there being key-in-TPM or something
similar. Nick On 9/21/16 10:33 AM, David Walker
wrote:
|
- [Per-Entity] TLS private keys and CDNs, David Walker, 09/21/2016
- Re: [Per-Entity] TLS private keys and CDNs, Nick Roy, 09/21/2016
- Re: [Per-Entity] TLS private keys and CDNs, David Walker, 09/21/2016
- Re: Re: [Per-Entity] TLS private keys and CDNs, chubing, 09/29/2016
- Re: [Per-Entity] TLS private keys and CDNs, David Walker, 09/21/2016
- Re: [Per-Entity] TLS private keys and CDNs, Nick Roy, 09/21/2016
Archive powered by MHonArc 2.6.19.