Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, yes, and YES!

The CAs are allowed to sell CA=YES certs, but that doesn't mean that a browser (or any other tool using certificate chains) needs to follow them. On the other hand, the argument would be that if the CA could always just approve anything that this third party asked for... same effect and well within their power. So perhaps we DO want CA=YES just so we can tell when some CA is being unreasonably liberal.



"Approving anything that the third party asks for" doesn't really work unless you give them a completely automated, very high speed process to do this with. The DLP boxes are generating the MITM certificates on-the-fly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: