• Valmond@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 month ago

    Since I set up a https website (lemmy) and had to deal with the hassle of certificates, I do wonder why you need another entity to churn out what’s basically a RSA key pair?

    Is it this you must trust the government again or is there some better reasons for it?

    • AHemlocksLie@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 month ago

      It’s to make sure you’re actually reaching your intended endpoint. If I’m visiting a site for the first time, how do I know I actually have THEIR certificate? If it’s self generated, anybody could sign a certificate claiming to be anybody else. The current system is to use authority figures who validate certificates are owned by the site you’re trying to visit. This means you have a secure connection AND know you’re interacting with the correct site.

        • AHemlocksLie@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 month ago

          I don’t know what the process is like to become a certificate authority. I imagine the answer is technically yes but realistically no, at least not as an individual. You’d be providing a critical piece of internet infrastructure, so you’d need the world to consider you capable of providing the service reliably while also capable of securing the keys used to sign certificates so they can’t be forged. It’s a big responsibility that involves putting a LOT of trust in the authority, so I don’t think it’s taken very lightly.