Hacker News new | ask | show | jobs
by rad_gruchalski 1608 days ago
> Maybe we actually need a better CA.

Go for it. Start one and tell us how it went.

1 comments

If ever I have too much free time, I'll spend it modifying firefox to support DANE.
I simply think your previous argument is disingenuous. We have a free to use CA who's code can be vetted, such mistakes can be caught, potential problems can be averted. If this is the price to pay, okay, so be it. Imagine what must fly under the radar of other CAs who do not have thousands of eyes vetting their code base - as in, those would never be visible.

So okay, maybe you don't have certs revoked and you don't need to restart your Traefik but are you really sure everything is okay?