the more I read about this Trustico incident, the more absurd it gets
what the actual fuck
@staticsafe I assume when I use a provider that works through Let's Encrypt, the provider is holding on to the keys rather than Let's Encrypt. Still depends on trusting someone else, but it's not the CA.
@staticsafe Good knowledge.
@Riley correct, in that case, the provider uses a tool that interfaces with Let's Encrypt's ACME API, the tool generates the CSR and the private key, submits the CSR to Let's Encrypt, Let's Encrypt does the validation process and if it passes, gives the cert back