|
|
|
|
|
by dilyevsky
2056 days ago
|
|
So exposing your internal infrastructure to the whole world and risking a 3rd party (CA) turning the keys (literally) to your kingdom to someone else is better than someone making a mistake that’s very easy to discover and correct? > Also, sometimes people need to access documents and emails from home computers and the company may use some devices on which it isn't possible to install the CA That’s a plus as far most security professionals are concerned |
|
That's not how certificates work. The CA doesn't have your private key. They could theoretically sign a fake certificate with your hostname but that risk is still present if you use a private CA and is mitigated by certificate transparency