What is wrong, how to be your own certification authority and self-sign for email encryption?

Is there a real reason to use a third-party certificate authority for my own email security?

(which means using S / MIME)

I found that I could become my own CAuthority and create my own self-signed root certificates ... and they work fine on my machines and mobile devices.

Is there any good reason to use third-party paid certificates instead of my own and signed ones that I control?

I keep thinking - the person or entity that I most trust the authority of my verified encrypted letters ... is ME! ... why would I allow an additional unverifiable entity to me in this communication chain? “If someone who sends emails is the others who know me and trust me to be him ..?” and why do I PLAN them?

I can understand if there is a connection between my commercial site and unknown outsiders who do not know me and make money ... but for personal email? between family and famous friends or compatriots?

Is there anything else that I don’t understand about public and private key encryption, which makes having an approved large third party certificates worth paying for?

I understand that an SSL third-party verifies when you do business on websites or trusted sites using your secure connection. But between people? it seems different ... the people you know personally are even more different. No?

+5
source share
5 answers

The only reason for using an external CA is that there is a common trust root between you and the other party. If you manage all the machines, for example, in a domain, then there is no reason, you cannot use your own CA. We have our own CA for the Exchange domain. This is actually much simpler than an external CA, because servers and clients will automatically receive CA certificates.

+7
source

-, - . , , , , , .

, . , , , , , , .

, CA , , , , . , , .

, "" () .

0

. , , , gmail/yahoo/hotmail, , ( , ).

Spf, dkim, certs.. , ?

postfix + letencrypt .

-1

, , , .

, . , . . SMIME , , , , - , 20 $/.

. , , . , , , ! - . . -. , . , , , .

-3

All Articles