Hacker News new | ask | show | jobs
by angry_octet 1285 days ago
It needs to be supported in the clients, both browsers and libraries. I'm actually mad that scope restrictions are not more commonly used, and that tooling is absurdly complicated.

It would be useful for internal CAs too, because they could be trusted for only a specific subdomain, eg *.intranet.acme.com.