|
|
|
|
|
by olliej
2785 days ago
|
|
Because the public keys are baked into the OS trust store. For the exact reason of not being able to get the keys from the internet if you don’t already have a root of trust. The other issues (trust worthiness of CAs in countries that have the ability to compel a ca to issue a fake cert -Australia say), are intended to be mitigated by the CT logging that is now required by the major trust stores. Sure your Aussie CA might issue a fake certificate, but in doing so they ensure they get a global distrust... |
|
Without this, we will always be dragging our feet in dropping CA trust, because it will leave some perfectly valid sites shit out of luck.