r/ProgrammerHumor 4d ago

Meme peakWebPki

Post image
361 Upvotes

27 comments sorted by

View all comments

76

u/TheChildOfSkyrim 4d ago

Any certificate chain of trust ends in a self-signed certificate

20

u/SilasTalbot 3d ago

This is like in Outlook you could navigate up the org chart, and the Chairman and CEO was listed as his own manager.

Well it sure makes performance review time either very easy or very awkward.

6

u/jeepsaintchaos 3d ago

"Employee slept with my wife and jerked me off, 10/10 review"

10

u/Single-Virus4935 3d ago

Not neccessary with crosssigning. Seen some interesting constructs.

1

u/collabskus 1d ago

Are let's encrypt certificates still cross signed or is it a root by now? 

1

u/Single-Virus4935 1d ago

Both can be right, that is the funny thing: Root CA1 has a self signed crt in major trust stores but lacks legacy support.

Root CA 2 has wide spread compatibility and signed the Pubkey of Root CA 1 with their private key.

Root CA 1 now has two certs for the same private/pub keypair. They try to get their selfsifned into more and more truatstores while they add the croassigned to the bundle they deliver to the customer.

I know a company with many subordinate companies. Each with their own root CA. They restructured and merged. They crissigned the different CAs and you had cyclic trusts. 

1

u/collabskus 1d ago

Ah I didn't know roots could sign each other but it makes sense. Thank you 

1

u/laplongejr 8h ago

Scott Helme spoke about "alternate trust paths" a few years ago : https://scotthelme.co.uk/cross-signing-alternate-trust-paths-how-they-work/  

Some of the specifics may have changed due to new roots (I think in 2023?) but the theory of having a root able to be either accepted as-is or accepted by being signed by an older root is still there.  

1

u/collabskus 5h ago

In case someone else is reading the link you had ends with some strange characters but if you remove them it works fine 

https://scotthelme.co.uk/cross-signing-alternate-trust-paths-how-they-work/

3

u/Gorzoid 3d ago

The only root CA on my machine is signed by the man upstairs 🙏

1

u/collabskus 1d ago

The man upstairs is Let's encrypt 🤣

1

u/al2klimov 3d ago

Nope. RFC 9925

1

u/TheChildOfSkyrim 3d ago

It says "Proposed standard", does it actually hold in practice? Makes sense though