www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC
www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC
The software's assumption is that (for some sites at least) the author can check what the "right" certificate is and if you see a different one that's wrong.
That clearly won't work for some sites any of the time, they use a CDN to present different behaviour including certificates in different places, and presumably the author weeds those out. But as we see here it can't work for _any_ site all the time, it will be inconsistent.
Is there any downside to this? I mean, I have several wildcard certs issued for each of my personal domains mainly because it's more convenient to get separate certs on each host with certbot than trying to sync certs from one host to another. Is there any reason I shouldn't do this?
A bad guy who gets any of the private keys associated with any of these certificates can use that to impersonate any service with the corresponding name, even a quite different one.
So say you've got mail.oefrha.example that's a mail server using a *.oefrha.example cert, and the Dread Pirate Roberts breaks into it, they can use that when impersonating your web server www.oefrha.example or your Q&A site faq.oefrha.example even if those are on totally different hardware that Roberts wasn't able to penetrate.
For older TLS (or SSL) versions there's a trick called implied authentication used with RSA. After showing the certificate, instead of your server signing something to prove it knows the corresponding private key, the client sends something across which your server decrypts. Only the real server could decrypt it with the private key to continue the conversation so authentication is implied. However, in doing this your server has to be _extremely careful_, because it's easy to give away information when things go wrong. If it's not careful enough, a bad guy doesn't learn the key but they can use your answers to work out how you'd sign RSA messages.
This means if you've got old-crap.oefrha.example which does TLS 1.0 with crappy RSA implied auth enabled so as to make it work with some rotten turn of the century tech, and it has a wildcard certificate, some bad guys can maybe exploit that to pretend they are www.oefrha.example even though your actual www.oefrha.example web server only speaks TLS 1.2 or newer with elliptic curves.
You say a "personal domain", and I don't recognise your name, so chances are that this just doesn't matter. We're not talking about something a bored teenager can do, but if real bad guys with resources are attacking you, then it's probably not a smart idea to have so many wildcards.
Edited: Repeatedly to try to get HN's half-arsed parser to stop ruining everything. Gave up. HN use a parser that has working escapes, or remove the parser and just say the site only has text too bad.
For a large organization, this probably just says that they have a lot of different systems and groups operating relatively independently with poor practices, which isn’t an immediate problem but suggests that they’re an easier target than some.
same for me is there reason why though?