3 ms·
Correct. It is a GlobalSign cert that was donated to the Node.js project. Once we became a company we had to stop using it, both from an abundance of caution, s
by seldo 13y ago
Correct. It is a GlobalSign cert that was donated to the Node.js project. Once we became a company we had to stop using it, both from an abundance of caution, security wise, since we were not the only ones who had the cert, but also because it wasn't right to be using a free cert for our new, for-profit entity.
But moving to our new, self-owned cert in a way that broke anything was avoidable, and a huge error on our part.
- STRML 13y agoI see. And that old cert will work with old npm clients? Additionally, what are your thoughts on signing the digicert CA with the npm CA as mentioned here [1], thus fixing old clients and avoiding another cert switch? 1. https://news.ycombinator.com/item?id=7322970 https://news.ycombinator.com/item?id=7322970
- seldo 13y agoAny npm downloaded after ~August of 2012, which is when the GlobalSign CA was added to the client: https://github.com/npm/npmconf/commit/d7ef61c8d9ae87f39482c554bd5cea62754bc57b https://github.com/npm/npmconf/commit/d7ef61c8d9ae87f39482c5... I believe we considered adding the npmCA and dismissed it, but it has been a long week and I can no longer recall why. I will bring it up and post an update here next week.
- STRML 13y agoThanks for the updates and finding the time to post during what's certainly been a hectic day.