2 ms·
Marsh, I understand your concern and I share it though I don't agree with the conclusion (re sticking head in the ground). With that said GlobalSign has commit
by rmhrisk 14y ago
Marsh, I understand your concern and I share it though I don't agree with the conclusion (re sticking head in the ground).
With that said GlobalSign has committed to implementing CT and we hope all other CAs agree to do the same as Adam points out earlier in this thread its the way to bring the desired transperancy.
That said it alone inst enough either, to start we also need TACK (and/or HSTS pinning), CAA, robust revocation checking and Name Constraints.
And while conversations like this are uncomfortable (certainly for me being on the receiving end) I think they help too.
- marshray 14y agoSo are you proposing that 3rd party sub-CAs be brought under public CT? I could get on board with that.
- rmhrisk 14y agoI believe for CT to "work" all CAs on the public internet need to participate. I also believe that certificate transparency by itself is insufficient and the other items I mentioned are also needed.