-
tom
> I've also heard reports indicating that chatterboxtown.us is rejecting new Let's Encrypt certificates. I am making my own certificate authority in response to google being able to control letsencrypt ↺
-
tom
Using it between friends for TLS and ipsec transit mode, but I'm not sure if anyone here would be willing to install it even with it being namespace scoped
-
freespoken.nz
OK, I've now reported this at xmpp:support@muc.5222.de?join
-
agh
>> I've also heard reports indicating that chatterboxtown.us is rejecting new Let's Encrypt certificates. > > I am making my own certificate authority in response to google being able to control letsencrypt How expensive is that? Or you talking self-signed CA certs?
-
Guus
I'm not sure there's much practical difference: running your own certificate authority means creating a self-signed certificate used to sign others, while using a self-signed certificate directly just uses that single certificate. In either case, you still have to convince peers to trust your chain: either the self-signed end-entity certificate or the self-signed root certificate.
-
agh
I have no idea what Tom meant. I was thinking they were talking about buying their place in the internet CA Cartel with their own business unit.
-
agh
That way, your signed entity would end up with all the CA's in your OS.✎ -
agh
That way, your signed entity would end up with all the other CA's in your OS. ✏
-
MattJ
That's the thing Google/Mozilla have control over though
-
MattJ
An XMPP CA ecosystem separate from the browser one is certainly not out of the question. In fact XMPP.net began life as a CA for XMPP servers.
-
agh
Interesting.
-
MattJ
But it's not a small task, to do it at scale securely
-
agh
> That's the thing Google/Mozilla have control over though Which is why they are against DANE. ↺
-
moparisthebest
wait what? Google has no control over DANE
-
agh
Only on adoption of it, I think.
-
agh
Did they not bail out on supporting DNSSEC or DANE in their platforms 12 or so years ago?
-
agh
My memory is fucked, but I recall a time when Google was supporting DNSSEC somewhere, maybe even in their browser, then they removed it.
-
agh
And you know, that DANE requires DNSSEC.
-
moparisthebest
god if we have to hate things google has changed their mind on that's literally everything
-
agh
OK true
-
agh
But what control does Google have on DANE?
-
agh
Apart from no longer implementing DNSSEC validation in the browser?
-
agh
And obviously Let's Encrypt was a massive diversionn✎ -
agh
And obviously Let's Encrypt was a massive diversion. ✏
-
icebound.dev
tom, you are better off using DANE.
-
freespoken.nz
> An XMPP CA ecosystem separate from the browser one is certainly not out of the question. In fact XMPP.net began life as a CA for XMPP servers. Wouldn't it be better to encourage adoption of DANE for authentication instead? ↺
-
moparisthebest
yep, and until then LE works fine