4 ms·
And that alarm has constantly been going off. CAs have consistently failed to abide by BR policies which would have otherwise gone unnoticed. Things like certl
by devrand 8y ago
And that alarm has constantly been going off. CAs have consistently failed to abide by BR policies which would have otherwise gone unnoticed.
Things like certlint have come about to help prevent misissuance, but I would wager that most CAs have not added it to their issuance pipeline.
I agree that CT is not the solution and ideally it would not be necessary, however, the number of issues found and still being discovered justifies it. Trusting CAs to just issue proper certificates has been a failed policy.