Earlier quoted context omitted.
Huh? We want wildcards so that if you sign up example.com we can give you a certificate for example.com and *.example.com. This has nothing to do with SANs.
However, that is apparently a deal breaker, which makes me suspicious because many organizations have no trouble implementing Let's Encrypt SSL despite the lack of wildcard support. That + Past Behavior = suspicion.
How not to run a CA
251–255 of 255 posts
Re: How not to run a CA
#252Earlier quoted context omitted.
Keeping nazis off of servers one owns/rents themselves is not censorship.
How is that not censorship? Their opinions are wrong and disgusting but kicking them as a customer for their beliefs is very obviously censorship.
Re: How not to run a CA
#253Browsers need to remove all CAs except Let's Encrypt. CAs have proven again and again to be ridiculously insecure, and the problem is that there is no penalty for their mistakes. So just remove them all, after a warning period: Let's Encrypt is enough. Or if they want to stay in business and be trusted by browsers, then require them to put up at least $100k in cash in escrow for each certificate they sign, which is f…
Yeah, Let's Encrypt doesn't support OV or EV certs...
Re: How not to run a CA
#254Earlier quoted context omitted.
However, that is apparently a deal breaker, which makes me suspicious because many organizations have no trouble implementing Let's Encrypt SSL despite the lack of wildcard support. That + Past Behavior = suspicion.
Which part is a deal breaker? I'm not sure what you are getting at.
Did your colleague mis-speak?
Re: How not to run a CA
#255Earlier quoted context omitted.
Which part is a deal breaker? I'm not sure what you are getting at.
I am quoting an earlier comment in this very thread: "We use several CAs to issue—Comodo, DigiCert, GlobalSign—and will be adding Let's Encrypt once they support i) SHA-2/ECDSA signatures and ii) wildcards." Did your colleague mis-speak?