2 ms·
I agree with Hanno here. There are great tools to make the CAs behave or at least make their mistakes being easily spotted: Name Constraints, DNS CAA records, C
by bugmen0t 9y ago
I agree with Hanno here. There are great tools to make the CAs behave or at least make their mistakes being easily spotted: Name Constraints, DNS CAA records, Certificate Transparency and, if you must, HPKP and much more.