4 ms·
Internal CAs are a pain because enrolling new CAs is difficult, especially without device management. It can also interfere quite badly with product testing. T
by fweimer 2y ago
Internal CAs are a pain because enrolling new CAs is difficult, especially without device management. It can also interfere quite badly with product testing.
Technically, it's not required for anyone but you to validate ownership of names further down the DNS tree once you have shown control over the DNS tree further up. Maybe combine it with the public suffix list to discourage misuse by certain service providers.