Dstack-TEE / Dstack-TEE/dstack-examples

Example of Letsencrypt handling

Đang mở
#6 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
encumbrance enhancement
Ngôn ngữ chính
Python
Star
27
Fork
26
Merge trung bình
1 giờ 25 phút
Pull request đã merge (30 ngày)
7

Mô tả

There are a few ways of automating domain handling from within an enclave.

- [x] 1. A starting point is the approach taken in teleport "trust but verify"...

The private key used to generate the certificate signing request is generated from within the enclave.

The owner of the DNS record isn't proactively prevented from issuing a non-TEE domain, but because certificate transparency provides a list of every issued certificate, we can show a remote attestation to explain every certificate that has been issued.

- [x] 2. Another improvement is a DNS feature called CAA, https://letsencrypt.org/docs/caa/ which limits the CAs that are authorized to issue certificates for a domain. This significantly reduces the potential for rogue CAs to create MITM attacks - only letsencrypt could do that. This is what is implemented here https://docs.phala.network/dstack/design-documents/tee-controlled-domain-certificates

- [ ] 3. Encumbered DNS: a final step (still to research) would be to encumber the account with the registrar that owns the account. In this way, a smart contract would practically control the DNS records.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.