Hacker News new | ask | show | jobs
by dilyevsky 1248 days ago
I believe zerossl chain (really sectigo) is trusted by more devices than the new isrg root (mostly old unupdated ones). Also zerossl has fewer limits in their acme implementation. Downsides are zerossl has some questionable security practices and also I think zerossl either dont support tls-alpn-01 validation or it’s just broken