Hacker News new | ask | show | jobs
by thatcks 1291 days ago
One of the problems with domain restrictions on CAs is that real world geography has turned out to not correlate with domain name 'geography' for general use. Organizations located in a country (or the EU or etc) will register their domains all over, instead of nicely restricting themselves to something under a single TLD or a small number of them, where they could use a restricted-scope CA. This mostly leaves you with organizational CAs, such as government ones (for the government's sites), and they seem to not have been too popular in practice.
1 comments

Seems like it would mirror how the registrar system works, where some registrars are able to register most TLDs and some are more regional.

I'm guessing that for some TLDs it would make even more sense like for .gov or .google or similar.