logoalt Hacker News

kachapopopowlast Thursday at 1:49 PM0 repliesview on HN

no, the private keys are yours - the root CA just 'signs' your key in a wrapper that is was "issued" by ex: letsencrypt, and letsencrypt just has one job: validate that you own the domain via acme validation.