| ▲ | mcny 2 days ago | |
I thought the whole point of the acme client was that the private key never leaves my server to go to let's encrypt servers. Now yes, if I am using cloudflare tunnel, I understand the tls terminates at cloudflare and they can share with anyone but still it has to be a targeted operation, right? It isn't like cloudflare would simply share all the keys to the kingdom? | ||
| ▲ | notpushkin 2 days ago | parent [-] | |
Yes. They could issue their own certificates, but we have CT to mitigate that, too. | ||