|
|
|
|
|
by tempay
965 days ago
|
|
> Your clients will only trust the certs for your CA, and those CAs have constraints in place so that we could never issue a certificate outside of your set of configured DNS names. Does this work in practice? I was under the impression that the extensions for restricting which domains a CA can use weren’t widely supported. |
|