2 ms·
I'd say no, though it depends on the provider. Afaict the vulnerability is simply "users can upload arbitrary certs and have the server use them based on SNI",
by tscs37 9y ago
I'd say no, though it depends on the provider.
Afaict the vulnerability is simply "users can upload arbitrary certs and have the server use them based on SNI", which does have some legitimate use cases (private CA)