7 ms·
The current PKI is geared toward ease-of-use and adoption. It can also be turned completely around: only trust a single root certificate. This design is often
by dikei 4y ago
The current PKI is geared toward ease-of-use and adoption.
It can also be turned completely around: only trust a single root certificate. This design is often used in client authentication: each client need to get its certificate signed by the one single CA that's trusted by the server.
- XorNot 4y agoRight but implementation wise we've never implemented as a default anything else. Domain suffix pinning is available as an extension, but that's all it is - very few TLS stacks support it and that's unlikely to ever change.