Addressing Linux’s Missing PKI Infrastructure
"we’re starting the development of upki: a universal PKI tool. This project initially aims to close the revocation gap through the combination of a new system utility and eventual library support for common TLS/SSL libraries such as OpenSSL, GnuTLS and rustls"
discourse.ubuntu.com/t/address…
Addressing Linux's Missing PKI Infrastructure
Earlier this year, LWN featured an excellent article titled “Linux’s missing CRL infrastructure”. The article highlighted a number of key issues surrounding traditional Public Key Infrastructure (PKI), but critically noted how even the available meas…Ubuntu Community Hub
Ani ty holubi nebudou 😄
schnedan
in reply to daniel:// stenberg:// • • •sounds like reinventing the wheel... first Linux has a servicemanager (yeah some don't like systemd, but I am not aware anybody has implemented a API compatible replacement yet). So this sounds like it should be a (background)service.
And efficiently fetching some kB or MB... Linux is already shipped with tools like R-Sync.
With that in mind, 60% of the needed infrastructure is already there, right?
mortn
in reply to daniel:// stenberg:// • • •zoug
in reply to daniel:// stenberg:// • • •GitHub - rustls/upki
GitHubF4GRX Sébastien
in reply to daniel:// stenberg:// • • •"Musty Bits" McGee
in reply to daniel:// stenberg:// • • •fraggLe!
in reply to "Musty Bits" McGee • • •Stefan Eissing
in reply to daniel:// stenberg:// • • •Hmm, mirroring Mozilla, then depending on canonical. Does not sound very decentralized for a planet wide pki infrastructure to me.
Sites wanting short reaction times seem better served with short lived certificates and fallback ACME CAs.
But what do I know of this?💁🏻♂️