3 pointsby plopilop4 hours ago1 comment
  • znpy3 hours ago
    > Rather than issuing individual certificates for every internal host, a wildcard for something like *.int.example.com covers everything under that subdomain.

    Congrats now one host is compromised and the certificate for the entirety of your private infrastructure is leaked.

    This post is really amateur-level it security.