4 ms·
That really isn't how this works. DigiCert don't have any 'power' as you suggest - the .be government are free to choose any CA they wish from those who are glo
by nickf 3y ago
That really isn't how this works. DigiCert don't have any 'power' as you suggest - the .be government are free to choose any CA they wish from those who are globally trusted. These are for serverAuth certificates, too, so no-one is talking about internal/top-secret/sensitive intra-government communications.
Even if you were paranoid enough to think a US company like DigiCert would 'do anything' - their issuance is subject to public scrutiny (something the EU proposal doesn't like) and malfeasance has very real consequences to the whole of Digicert's business.
- ginko 3y agoDigiCert's HQ is a 10 minute drive away from the NSA's Utah Data Center. I don't think you you need to be particularly paranoid to think there might be foul play there.
- sam_lowry_ 3y agoBefore the change, the Belgian government did not have to choose any CA from "globally trusted". They were one of the globally trusted CAs. I think the eIDAS is trying to revert the trend and put Europeans back in charge of their CAs. See for instance the eSignature Trusted Lists like this one [1] I understand and support the intention. European Commission is just too bad at implementing it. [1] https://ec.europa.eu/digital-building-blocks/DSS/webapp-demo/tl-info/tl/TL-61C0487109BE27255C19CFF26D8F56BEA621E7F381A7B4CBE7FB4750BD477BF9 https://ec.europa.eu/digital-building-blocks/DSS/webapp-demo...
- pieter_mj 3y agoThat is how what specifically doesn't work? Could you specify? Digicert's root certificates serve all purposes, not just serverauth. NSA can and will use CA certs to mitm when they want, there's no need for overt malfeasance on Digicert's side.