Hacker News new | ask | show | jobs
by closeparen 2055 days ago
Typically an internal CA adds to the certificate trust store rather than replacing it.
1 comments

Yes you are correct here (although I’ve seen both methods). At least 3rd party won’t easily know which hostnames to fake though