3 ms·
1) If that's the case they should be able to prove they are legitimate without to much effort. If a CA can't prove they are legitimate, well. Err.. they probabl
by kseifried 4y ago
1) If that's the case they should be able to prove they are legitimate without to much effort. If a CA can't prove they are legitimate, well. Err.. they probably need to be booted then.
2) Correct but there are also many CA's that have managed to do a good job here. Why should we allow poorly behaved CAs in when it affects potentially billions of devices and people?
As for the external audits correct, they are very narrow in scope, there are also no requirements around change of control (e.g. company A buys an existing root CA).