Hacker News new | ask | show | jobs
by zwp 5490 days ago
"a lot of "real" certificates depend on this CA"

How many? did you estimate from sequential serial number allocation?

I am surprised (even if it turns out this is "just" an encrypted webserver key) that they aren't using hardware keys: (a) it's their core business (b) they appear competent (CTO posts to technical mailing lists) (c) they have a /29 so aren't just a single IP on an inaccessible low-end VPS.

ssllabs.com gives them a C rating.