4 ms·
Don’t you have to trust the CA to actually log all the certs they issue? What’s to stop a rogue CA from logging all but a few key certs?
by snoopy_telex 4y ago
Don’t you have to trust the CA to actually log all the certs they issue? What’s to stop a rogue CA from logging all but a few key certs?
- pifm_guy 4y agoAnyone else can log a cert too. There was talk of Chromium logging any cert that chains to a public root that they find un-logged.