4 ms·
Yeah there's a GitHub repo behind this and there's comments from past times it has expired. Essentially it requires a public CA to issue an EV cert for them, wh
by cipherboy 4y ago
Yeah there's a GitHub repo behind this and there's comments from past times it has expired. Essentially it requires a public CA to issue an EV cert for them, which is hard to maintain and rotate. I think Mozilla and DigiCert worked on this iirc.
- cmeacham98 4y agoMany of their other non-EV certificates are expired as well, for example: https://sha384.badssl.com/ https://sha384.badssl.com/
- selcuka 4y agoTo be fair finding working SSL sites is easy. Broken ones, especially for uncommon reasons, are the problem. I have used BadSSL for such tests many times in the past.
- cipherboy 4y agoI believe 384 has the same problem: most CAs use RSA-2048/SHA-256 signatures and very few do 2048/384 (which this certificate is doing), especially on demand (ACME has no parameter to control hash function selection by the requester for instance) SHA384 with P-384 is much more common (and tested elsewhere on the site); what is unique about this one is using a larger hash with RSA keys. Like some of the other certs, it requires partnerships with CAs willing to bend their process a little for the sake of publicly available test infra.