Live data from Hacker News

How not to run a CA

blog.koehntopp.info

251–255 of 255 posts

Re: How not to run a CA

#251

Earlier quoted context omitted.

Huh? We want wildcards so that if you sign up example.com we can give you a certificate for example.com and *.example.com. This has nothing to do with SANs.

However, that is apparently a deal breaker, which makes me suspicious because many organizations have no trouble implementing Let's Encrypt SSL despite the lack of wildcard support. That + Past Behavior = suspicion.

Which part is a deal breaker? I'm not sure what you are getting at.

Re: How not to run a CA

#252
post #218
post #212

Earlier quoted context omitted.

Keeping nazis off of servers one owns/rents themselves is not censorship.

How is that not censorship? Their opinions are wrong and disgusting but kicking them as a customer for their beliefs is very obviously censorship.

A business transaction requires the consent of two parties. “I choose not to do business with you” is not censorship; the nazis are free to go and stand up their own servers.

Re: How not to run a CA

#253
post #78

Browsers need to remove all CAs except Let's Encrypt. CAs have proven again and again to be ridiculously insecure, and the problem is that there is no penalty for their mistakes. So just remove them all, after a warning period: Let's Encrypt is enough. Or if they want to stay in business and be trusted by browsers, then require them to put up at least $100k in cash in escrow for each certificate they sign, which is f…

Yeah, Let's Encrypt doesn't support OV or EV certs...

EV has been proven a lot less useful than thought : https://arstechnica.com/information-technology/2017/12/nope-...

Re: How not to run a CA

#254

Earlier quoted context omitted.

However, that is apparently a deal breaker, which makes me suspicious because many organizations have no trouble implementing Let's Encrypt SSL despite the lack of wildcard support. That + Past Behavior = suspicion.

Which part is a deal breaker? I'm not sure what you are getting at.

I am quoting an earlier comment in this very thread: "We use several CAs to issue—Comodo, DigiCert, GlobalSign—and will be adding Let's Encrypt once they support i) SHA-2/ECDSA signatures and ii) wildcards."

Did your colleague mis-speak?

Re: How not to run a CA

#255

Earlier quoted context omitted.

Which part is a deal breaker? I'm not sure what you are getting at.

I am quoting an earlier comment in this very thread: "We use several CAs to issue—Comodo, DigiCert, GlobalSign—and will be adding Let's Encrypt once they support i) SHA-2/ECDSA signatures and ii) wildcards." Did your colleague mis-speak?

No
Post reply on HN