I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

  • pdl@social.tchncs.de
    link
    fedilink
    arrow-up
    2
    ·
    9 days ago

    @flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
    The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA.

    • pdl@social.tchncs.de
      link
      fedilink
      arrow-up
      1
      ·
      9 days ago

      @flandish If US authorities want to fake my server, they can use any CA, regardless which CA I originally used.
      Of course, US authorities can force Letsencrypt to revoke my certificates and block any renewing. This is very unlikely to happen. If it happens, I have to change my CA. There would be a downtime for my private services, but there is no data corruption or data loss on my servers.