3 ms·
It seems like its an important thing to be able to express. They are extending their trust to the new CA. I believe this information is available to clients if
by ColinDabritz 11y ago
It seems like its an important thing to be able to express. They are extending their trust to the new CA. I believe this information is available to clients if they wanted to choose to reject cross signing.
You're right that this sort of broad power is scary, but I think it's being used reasonably in this context. Do you have specific concerns you are afraid of? The only problem I thought of was a compromised CA cross-signing a malicious CA, but if they are compromised, you could just issue the main CAs certs anyway.