3 ms·
Why?
by devrandoom 1y ago
Why?
- arccy 1y agoFor a server auth cert, you validate that the thing you connect to has a cert for the same name. For a client cert issued by web pki, all you know is that they've somehow obtained a cert for some name, you don't know if it's legit or not, since it doesn't come from connecting to the name. So kind of useless for trust.