4 ms·
That translation makes no sense. There's nothing in there that allows Google to deploy their own private keys and certificate on people's servers. > This [well
by ramchip 2y ago
That translation makes no sense. There's nothing in there that allows Google to deploy their own private keys and certificate on people's servers.
> This [well protected] certificate must both be issued from a trust hierarchy [which isn't Google and]
You should check out the issuer on the google.com certificate :)
Also, certificates are public data. They're not meant to be "well protected", they're sent to everybody connecting to the website. Maybe that's the misunderstanding? The private key is not issued by the certificate authority, it's issued by the server's operator. The CA only ever sees the public key.