310
you are viewing a single comment's thread
view the rest of the comments
[-] krellor@kbin.social 11 points 1 year ago* (last edited 1 year ago)

I use self signed certs for thinclient authentication. Generate self signed cert, load into AWS workspaces, sign device certs with root, and only machines that have the cert installed and pass the username password prompt will get through the AWS service broker. I can't see how using a CA signed cert helps me in any meaningful way. If I lose trust in the cert, I revoke it myself from the service.

[-] nickwitha_k@lemmy.sdf.org 1 points 1 year ago

Use of a CA (private CA would be my thought in this case) gives you greater ability to manage certs without needing to manually revoke and the ability to verify authenticity. You're already doing most of the work to run a private CA, TBH. Just, instead of signing from the machine, you add your private CA's intermediate cert to the trusted CAs on your hosts, and generate CSRs on your new hosts for your CA to sign.

Signing from the machine that uses a cert gives it greater authority and increases the "blast radius" if it gets compromised.

[-] krellor@kbin.social 2 points 1 year ago

I do have a private ca service running on an internal ec2 instance, but all the AWS workspaces broker checks is if the device cert being passed by the thinclient was signed by one of the two signing certs you've loaded into the service, so the private ca itself still doesn't manage revocation in this case.

I do appreciate the suggestion. My main goal in sharing this use case was to show folks that there are many places certificate are used that let's encrypt isn't geared up to solve. Other examples are things like signing Microsoft API requests, etc.

Anyway, have a great day!

[-] nickwitha_k@lemmy.sdf.org 1 points 1 year ago

Oh fun. Thanks for sharing! Have a great day, yourself!

this post was submitted on 02 Oct 2023
310 points (93.8% liked)

Sysadmin

7641 readers
1 users here now

A community dedicated to the profession of IT Systems Administration

No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
!lemmy@lemmy.ml
!lemmyworld@lemmy.world
!lemmy_support@lemmy.ml
!support@lemmy.world

founded 1 year ago
MODERATORS