4 ms·
RapidSSL is owned by GeoTrust, which is owned by Verisign. You can read all about GeoTrust's certificate practices here: http://www.geotrust.com/resources/cps
by cscott 18y ago
RapidSSL is owned by GeoTrust, which is owned by Verisign.
You can read all about GeoTrust's certificate practices here: http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.pdf http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Versi...
The results of their KPMG audit here:
https://cert.webtrust.org/SealFile?seal=650&file=pdf https://cert.webtrust.org/SealFile?seal=650&file=pdf
And their entry into Mozilla here:
https://bugzilla.mozilla.org/show_bug.cgi?id=409236 https://bugzilla.mozilla.org/show_bug.cgi?id=409236
- tptacek 18y agoOf course, all the KPMG audit really says is "GeoTrust has a policy about checking the documentation of people who request certificates", and there's part of the problem: there's no way for a CA to make an attestation that they've implemented the technology competantly, because no third party will certify that attestation.