Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FAQ Entry for Passwords on JKS / PKCS#12 #1347

Open
SgtCoDFish opened this issue Nov 17, 2023 · 0 comments
Open

FAQ Entry for Passwords on JKS / PKCS#12 #1347

SgtCoDFish opened this issue Nov 17, 2023 · 0 comments

Comments

@SgtCoDFish
Copy link
Member

We [1] generally agree that passwords on JKS / PKCS#12 files solve no problems in any practical threat model when using cert-manager or trust-manager. That can be incredbly unintuitive for users who see the word "password" and assume it must be a security feature.

We should document why we take the position that this is not a meaningful security feature on the website, so we can refer people to that text.

[1]: This was discussed in our standup on 2023-11-17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant