3 ms·
This is lame news. But what I'm curious about is: What are they going to do (if anything) to validate the upstream certificates? - What will their upstream roo
by rakslice_ 11y ago
This is lame news.
But what I'm curious about is: What are they going to do (if anything) to validate the upstream certificates?
- What will their upstream root certificate policy be?
- If they MITM any old upstream certificate, how will they mitigate the huge target they are painting on Kazakh Internet users?
- peeters 11y agoI would assume their root trust store could be similar to what your browser would use. i.e. a curated set of root CAs with CRL subscription.