3 ms·
The original abandoning of the self-signed cert was because self-signed certs were a bad idea. The issue that post refers to (it is a little unclear, because w
by seldo 13y ago
The original abandoning of the self-signed cert was because self-signed certs were a bad idea.
The issue that post refers to (it is a little unclear, because we ourselves were a little unclear what had gone wrong at that point) is when we broke older clients by moving to a non-GlobalSign cert. We cleared that up here: http://blog.npmjs.org/post/78165272245/more-help-with-self-signed-cert-in-chain-and-npm http://blog.npmjs.org/post/78165272245/more-help-with-self-s...
We had already planned to move to a new cert before the security disclosure, and hadn't anticipated the size of the problem with a non-GlobalSign cert, so although the two happened pretty much simultaneously, they weren't really related.