|
|
|
|
|
by Jensson
962 days ago
|
|
The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate. It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Google thinks it is bad. |
|
Mozilla has proposed text[1] that would make clear that the requirement is only to display identity information, but this text has not been adopted.
[1] https://securityriskahead.eu/wp-content/uploads/2023/09/Mozi...