Hacker News new | ask | show | jobs
by kazazes 3781 days ago
Wouldn't it be more reasonable for browsers to not cache them at all and universally reject missing intermediate certificates? (IIRC correctly, Chrome doesn't mind but Firefox will give you the train conductor)
1 comments

It would definitely eventually reduce the frequency of this configuration mistake.

Firefox definitely does cache intermediates (I've seen it do so as recently as today).