Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How are the CA certificates obtained? #1

Open
brycefisher opened this issue Apr 19, 2016 · 3 comments
Open

How are the CA certificates obtained? #1

brycefisher opened this issue Apr 19, 2016 · 3 comments

Comments

@brycefisher
Copy link

brycefisher commented Apr 19, 2016

I'd love to understand:

  1. Where these certificates came from?
  2. How they can be verified against a remote checksum? (Or other cryptographic verification system)
  3. How frequently this list will be updated?
  4. If revocations are taken into consideration in this list?

Thanks! This project is much appreciated.

@broady
Copy link

broady commented Jun 22, 2016

@brycefisher good questions. I had the same questions, so I made broady/cacerts, since centurylink/ca-certs looks pretty dead, which is rather dangerous.

For mine,
1: from Debian's ca-certificates package
2: verified by GPG signing, but the image built by me isn't signed. Copy the source and build your own if you are concerned about my/dockerhub's integrity. I can sign (via keybase.io) something if you'd like.
3+4: no plans yet. How does Debian handle that?

@brycefisher
Copy link
Author

Awesome! Thanks so much, @broady

cc @thomshutt @geneticgenesis @stuarthicks

@stuarthicks
Copy link

@broady @brycefisher Thanks! I like that approach, makes it really clear to see where the certs came from (and is reproducible). 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants