3 ms·
I made a comment up-thread, but name-constrained CAs can issue for anything. It's enforced client-side, and not supported in far, far too many places to work. Y
by nickf 3y ago
I made a comment up-thread, but name-constrained CAs can issue for anything. It's enforced client-side, and not supported in far, far too many places to work. You'd be giving everyone the ability to issue for anything.
Not to mention that running any kind of public CA is harder to do properly than most people thing.
I get the negativity towards public CAs, but much of what you said isn't quite right, either.
- Nextgrid 3y agoThe only "safe" way to introduce these would be to make a certificate format that's intentionally incompatible with existing implementations; that way only new implementations (which are aware of the domain constraint) will accept it where as old implementations would just reject the certificate as invalid/corrupt.