#424 Fedora package for step-ca from smallstep
Closed: published by rlengland. Opened by rlengland.

Article proposal: I am testing a Fedora package for step-ca from smallstep. The company offers a company repo, that tries to support Fedora but this will be a native Fedora package. Once the package is accepted (still waiting on yggdrasil-network to be reviewed), I planned to submit on article on the Evil TLS Cabal that can MITM your browser connections since mainstream browsers trust their CAs for absolutely everything by default.
I noticed when submitting the yggdrasil-network package that Fedora auto generates a COPR build for each SRPM submitted. (Great feature.) So the article could actually happen before the step-ca package is accepted. I've seen other articles talk about COPR packages.
After the conspiracy stuff in the intro, the article will be about running your own private TLDs, how easy it is with the smallstep, httpd/nginx and acme-tiny packages in Fedora, and why Big Corps do it for their own internal infrastructure. The audience is self-hosters using Fedora, and why they (alone or in conjunction with friends) should have their own TLD, DNS servers, and ACME CAs supporting it (along with the ICANN/Cabal TLDs and certs used by normies).

Unsolved problem is limiting trust for CAs by mainstream browsers. Apart from the TLS cabal, if strangers load your CA and the browser trusts it for everything (rather than just the private TLDs it is for), then you can MITM all their connections, just like the TLS cabal CAs! I get all kinds of answers along the lines of RFC5280 (x509 extensions limiting authority) - but those all assume complete trust in the loaded CAs. Note that the TLS cabal itself sounded this alarm when they stopped certifying .RU domains and Russia set up their own national CA. There should be a way to trust the Russian CA only for .RU domains.


Metadata Update from @sdgathman:
- Issue assigned to sdgathman

@sdgathman I would suggest, perhaps, not using the terms 'evil cabal' and 'cabal'. They may be inflammatory to some and using a less pejorative word might forestall a flame war.

Thank you for your understanding and consideration. Looking forward to your article.

The "group" is unnamed as far as I know. What do you call them? The "Global TLS Committee"? Anything shorter? At least ICANN has a name and acronym.

Ah, I think is cabforum.org. They vote on what CAs to include in browsers (and who is in the club).

In the days of WEF, "forum" has similar negative connotations to "cabal". But at least it is not secret.

I might suggest "bloc", "coalition", or "alliance", though to some "bloc" may be negative. Some definitions of "cabal" include the the concept of secretive or intrigue, that was my concern.

I admit, up front, that I am not intimately familiar with the operation of ICANN or the nuances of security as related to them.

I might suggest "bloc", "coalition", or "alliance", though to some "bloc" may be negative. Some definitions of "cabal" include the the concept of secretive or intrigue, that was my concern.

I admit, up front, that I am not intimately familiar with the operation of ICANN or the nuances of security as related to them.

If I have it right, they call themselves a "forum". cabforum.org. The forum is independent of ICANN - which provides a globally centralized DNS root (list of "official" TLDs). cabforum.org votes on which CAs to trust for everything by default in mainstream browsers.

@sdgathman "Forum" sounds good to me. Neutral and inclusive.

Submitted package review: https://bugzilla.redhat.com/show_bug.cgi?id=2418762

Writing an article is actually an excellent way to test the packaging for the new users (in my imagination).

Started article: https://fedoramagazine.org/?p=42809&preview=true&preview_id=42809

Metadata Update from @rlengland:
- Custom field preview-link adjusted to https://fedoramagazine.org/?p=42809&preview=true

@sdgathman I've added a featured image to your article. Let us know if it meets your approval. Suggestions for alternatives accepted.

Issue status updated to: Closed (was: Open)
Issue close_status updated to: published

Metadata