|
|
|
|
|
by JoshTriplett
3524 days ago
|
|
I hope that's just a "give us time to ease people into it" step. Most private-use-only CAs don't have the infrastructure for CT yet, so requiring it right away would cause a problem. But eventually it needs to happen, and all CAs any browser trusts need to require CT. |
|
Currently, CT logs have a list of roots that may submit to their log. If you run your own self-signed CA, you cannot (usually) use these logs, and there is a lot of effort and little benefit to running your own log setup.
CT tries to protect relying parties from bad issuers, but when the relying party is the same person as the issuer, it is not as beneficial.