8 ms·
Thanks Adam, yes these are not MITM certificates. They are used by large environments like Google and Microsoft to issue certificates for their assets and peop
by rmhrisk 14y ago
Thanks Adam, yes these are not MITM certificates.
They are used by large environments like Google and Microsoft to issue certificates for their assets and people.
They are contractually and technically (new but now standard) prohibited from using them for malicious use cases including MiTMs.
They are audited to conform with those terms and must meet the same requirements a certificate authority in the Mozilla guidelines.
- ivanr 14y agoAre they audited by GlobalSign, or by an independent third-party (i.e., same as all other CAs)?
- rmhrisk 14y agoFor us we require CAs that are not technically constrained to be independently audited to WebTrust for CA requirements, Moving forward thanks to Mozillas new policy the same will be true for all CAs.