5 ms·
There are so many dodgy root certs these days. First thing I do is delete a BUNCH of them when installing or upgrading a browser.
by midislack 4y ago
There are so many dodgy root certs these days. First thing I do is delete a BUNCH of them when installing or upgrading a browser.
- ohCh6zos 4y agoIs there a decent guide somewhere of what is safe to remove? I feel like I should prune root CAs, but also like I would need to know a lot more.
- pabs3 4y agoMaybe delete everything except Lets Encrypt and then re-enable ones for the sites you regularly visit that are now broken.
- Scaevolus 4y agoYou can get pretty good coverage (>90%) by just having the top 6 CAs (IdenTrust, DigiCert, Sectigo, GoDaddy, Let's Encrypt, GlobalSign): https://w3techs.com/technologies/overview/ssl_certificate https://w3techs.com/technologies/overview/ssl_certificate
- ohCh6zos 4y agoThat's an excellent idea.
- ttyprintk 4y agoHow to remove on Debian and family: sudo dpkg-reconfigure ca-certificates