4 ms·
> The ability to answer arbitrary HTTP requests on a server is sufficient to get a publicly-trusted certificate from any number of CAs. I'm saying you have to
by wfunction 9y ago
> The ability to answer arbitrary HTTP requests on a server is sufficient to get a publicly-trusted certificate from any number of CAs.
I'm saying you have to know what response to GIVE, don't you? You can't just give a random response...
- problems 9y agoThe CA tells you what response to give on that new account you signed up.
- wfunction 9y agoThanks, that didn't occur to me since I was mostly thinking of EV certs for some reason.
- pfg 9y agoThere's nothing to stop you from creating a new account at the CA of your choice, asking for a validation token, and putting it wherever it needs to be.