|
|
|
|
|
by Plasmoid
481 days ago
|
|
There is just one thing missing from this. Name Constraints. This doesn't get brought up enough but a Name Constraint on a root cert lets you limit where the root cert can be signed to. So instead of this cert being able to impersonate any website on the internet, you ratchet it down to just the domain (or single website) that you want to sign for. |
|
https://github.com/FiloSottile/mkcert/issues/131
https://github.com/FiloSottile/mkcert/pull/113
Hopefully Filippo revisits this now that it's broadly supported.