Live data from Hacker News

TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

tinycert.org

11–20 of 40 posts

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#11
post #7
post #5

Earlier quoted context omitted.

We know. They say very clearly on the front page that one of their advantages is: > Generate and manage SSL certificates quickly and easily without looking up complex OpenSSL commands.

But openssl commands aren't complex. Confusion ensues.

OS X includes a convenient app for all this https://imgur.com/zvCzT5l

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#14
It could be i'm totally missing the use-case for this, but personally I think if you can't take the 30 minutes to google one of the hundreds of guides that use OpenSSL commands and precompiled win32 binaries to generate three files you shouldn't be trusted with providing security for a website. Who are these people who need SSL and don't have 30 minutes to learn this once?

There are tons of scripts and other tools that handle the commands for you, too. Do I really need to sign up for yet another website just to perform one operation? (No, and neither should you)

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#16
post #2

I believe this was mentioned last time TinyCert appeared on HN, but a self-hosted version of this would be more ideal. I personally use etcd-ca[0] to ease management of my own certificates. [0] https://github.com/coreos/etcd-ca

As you say, I'd prefer to run this sort of thing locally - half the point of running your own CA is that you have full control over it.

I wrote caman (https://github.com/radiac/caman), a bash script wrapper for openssl with what looks like a similar syntax to etcd-ca. I posted about it on HN a while back, but it now also supports SAN certificates and intermediate CAs.

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#17
post #6

The fact that they keep your private keys in their database is what makes this a bad idea to use. Cannot see what kind of people this service is targeted to, since the ones who understand what a CA is and need to sign their own certificates probably already know how to use OpenSSL.

OpenSSL's CLI is pretty annoying, and for many (like me!) it mostly consists of copy-pasting commands into a text editor, modifying them slightly, and pasting them into a terminal. Could be better. But yeah, trusting a third party with your private keys isn't an answer.

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#18
It seems nice! A few days back I was playing a bit with golang's crypto and examples and I created a small cli app[1] to generate CAs and private key - certificate pairs signed by them. I wanted to create a small web service on top too (no need for sign up though, just check some fields and download a zip with your files) but haven't find time.

The most difficult problem imo, remains the management and not the creation of the keys and certs. I occasionally use them to connect backend services securely, so I have to install the root cert to every server OS and every JVM based app (here we create a keystore). Then I have to install each private key and certificate to the appropriate service. If the service is JVM based we also have to adjust its command line switches. Should a private key get stolen and we have one root CA for all services, we should delete and recreate everything. PKI is complex and with tens or hundreds of services its almost impossible to manage. Even the simplest task, like downloading a file from a nexus repository by a JVM based app using https and a free StartSSL certificate is very hard, since Oracle doesn't include StartCom's root CA.

[1] https://github.com/andmarios/quickcert

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#19
post #9

They mention StartSSL for production certificates. Beware that while creating certificates with them is gratis, REVOKING them will cost you money. https://www.techdirt.com/articles/20140409/11442426859/shame...

They actually have the most reasonable business model, as they only charge you for services where human interaction is required (fe checking your credentials or adding your certificate to the revocation list), anything else like signing your certificate is free.

Re: TinyCert – Become Your Own PKI/CA Authority in a Matter of Minutes

#20
I quite like the idea of TinyCert and often wanted to do something similar myself. Although creating a private CA is not a lot of work initially, maintaining it is a hassle, especially when you'd rather be doing something else. TinyCert could be useful for development teams (and other similar non-security-critical uses) to get rid of self-signed certificates altogether.

However, for me, the fact that they have all the private keys is a deal breaker. Further, I'd like to see the certificates name-constrained to specific development hostnames. And I don't like the fact that the keyUsage and extendedKeyUsage fields are not locked down. If I am going to install a private CA root, I want to have the smallest possible attack surface.

Overall, if they offer this as something that can be locally installed, it could be a useful product. Especially if it integrates with a low-cost HSM, for example https://www.nitrokey.com/

In the meantime, for anyone looking for good documentation on how to achieve the same using just OpenSSL on the command line, I have an easy-to-follow guide as part of my OpenSSL Cookbook:

https://www.feistyduck.com/library/openssl-cookbook/online/c...

Post reply on HN