Private key redaction: Ur doin it rong (2020)
1–10 of 34 posts
Re: Private key redaction: Ur doin it rong (2020)
#2Re: Private key redaction: Ur doin it rong (2020)
#3That's a pretty brutal bit of public shaming. Would it not have been better for the security community at large to instead reach out to Sven and have him address the issue privately?
Re: Private key redaction: Ur doin it rong (2020)
#4That's a pretty brutal bit of public shaming. Would it not have been better for the security community at large to instead reach out to Sven and have him address the issue privately?
Re: Private key redaction: Ur doin it rong (2020)
#5I wish this were a standardized thing every CA had to have, to avoid things like this:
> As of the time of writing, that certificate is not marked as revoked
Re: Private key redaction: Ur doin it rong (2020)
#6That's a pretty brutal bit of public shaming. Would it not have been better for the security community at large to instead reach out to Sven and have him address the issue privately?
I've changed it from https://www.hezmatt.org/~mpalmer/blog/2023/06/12/private-key... now.
Re: Private key redaction: Ur doin it rong (2020)
#7Personally I've always liked redacted keys because it makes it clear to users what they should expect.
Does this system want a PEM or a DER or a CER or a CRT or a JKS or a P7B or a P11? Or some vendor-specific format? The public key or the private key? Or both in the same file? A literal value, or a filename of a certificate on disk? A keyring?
It'd all be a heck of a lot easier if we didn't have such a mess of key formats.
Re: Private key redaction: Ur doin it rong (2020)
#8That's a pretty brutal bit of public shaming. Would it not have been better for the security community at large to instead reach out to Sven and have him address the issue privately?
Thanks. How about we change the URL to the more general article, which has more information and doesn't shame anybody. I've changed it from https://www.hezmatt.org/~mpalmer/blog/2023/06/12/private-key... now.
Re: Private key redaction: Ur doin it rong (2020)
#9I would define replacing the entire body of the key as redacting a private key. I would define the behaviour of the author as advocating against as partially redacting a private key.
Re: Private key redaction: Ur doin it rong (2020)
#10Why redact keys with PRIVATE KEY here when you can have more fun with it. You can put any base64 in there, put a nice image file in there (a logo if you're a boring company, a meme if you're writing a blog).