4 ms·
Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.
by nickf 8mo ago
Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.
- ahmedtd 8mo agoI don't think this is true. It's something that could be useful, with some sort of ACME-like automated issuance, but should definitely be issued from a non-WebPKI certificate authority.
- account42 8mo agoIt does if the "client" in the TLS sense is really a public server in a federated network. Like for example in XMPP which you may have heard of.
- direwolf20 8mo agoThen you specify your protocol to accept server certs from clients