3 ms·
I'm surprised and a bit skeptical that every CA (except for one) randomizes serial numbers without it being published in a standard or guidance document somewhe
by cscott 18y ago
I'm surprised and a bit skeptical that every CA (except for one) randomizes serial numbers without it being published in a standard or guidance document somewhere. Best practice usually has something worse than a (n - 1) distribution.
- jhancock 18y agowas the "one" in those articles? I didn't see. Anyway, who do you trust to buy certs from? I need to get a new one soon and would like recommendations.
- cscott 18y agoWhat's slightly ironic is trust doesn't matter for the buyer. As long as you purchase your certificate from a CA well placed in the major browser vendors, you're good to go. Edit: Here's a list of Mozilla's included certificates: http://www.mozilla.org/projects/security/certs/included/ http://www.mozilla.org/projects/security/certs/included/