|
|
|
|
|
by octoberfranklin
1608 days ago
|
|
If they didn't fail open, every time a CA's website went down every single website that used their certificates would go offline as well. You can imagine the DDOS-ransomers licking their lips at this possibility. No, "fail open" has always been the only possible way to implement this. Which is why it's a broken idea from the start. |
|
That's not correct. OCSP stamps exist to prevent that kind of a problem.