3 ms·
The fact that some root stores/browsers don't trust some CAs is actually quite common. There will be some cross-sign from another CA that is trusted in Firefox
by 0xxon 6y ago
The fact that some root stores/browsers don't trust some CAs is actually quite common. There will be some cross-sign from another CA that is trusted in Firefox in this case.
Stuff like this is quite common; we published a paper on this recently if you are interested in details: https://arxiv.org/abs/2009.08772 https://arxiv.org/abs/2009.08772
- sleevi 6y agohttps://medium.com/@sleevi_/path-building-vs-path-verifying-the-chain-of-pain-9fbab861d7d6 https://medium.com/@sleevi_/path-building-vs-path-verifying-... also has some utilities to visualize this using JS to explore these relationships, and understand the code tradeoffs.