4 ms·
I will add that in many "bigger orgs" they rely on external services/audits to identify certs signed outside of their process and use tools of the trade (like C
by wstuartcl 8y ago
I will add that in many "bigger orgs" they rely on external services/audits to identify certs signed outside of their process and use tools of the trade (like CAA records) to restrict certs being generated willy-nilly. If you are in a large org that does not do this -- raise it to the CSO. The fact that there are rogue certs in an org that may fail because of this CA removal action is the least of the orgs concerns.