Hacker News new | ask | show | jobs
by tempay 2197 days ago
The issue is that some of their customers have pinned DigiCert so they have two choices:

* pay whatever DigiCert demands for a new certificate * accept that some of their customers will break

Doing this two weeks before the old certificate expires puts them in a difficult situation for negotiating, especially now they've committed to getting a new DigiCert certificate.

1 comments

It seems like the solution to this is to implement both but charge customers to use the DigiCert chain. "Oh, you went and pinned something that you shouldn't have? That's fine; you can either fix it yourself or pay us to support your mistake."