logoalt Hacker News

mcnylast Thursday at 1:31 PM1 replyview on HN

I thought the whole point of the acme client was that the private key never leaves my server to go to let's encrypt servers. Now yes, if I am using cloudflare tunnel, I understand the tls terminates at cloudflare and they can share with anyone but still it has to be a targeted operation, right? It isn't like cloudflare would simply share all the keys to the kingdom?


Replies

notpushkinlast Thursday at 1:39 PM

Yes. They could issue their own certificates, but we have CT to mitigate that, too.