Hacker News new | ask | show | jobs
by josephcsible 1316 days ago
I wish the TLS Name Constraints extension were widely supported. Then browser vendors could just say that until that law gets repealed, they won't accept root CAs from any Turkish entities without a Name Constraints extension limiting them to only sign within the .tr TLD.
1 comments

X.509 Name Constraints are widely supported in browsers at this point - ref. https://bettertls.com - at least for DNS SANs and for the common cases.