|
|
|
|
|
by agwa
819 days ago
|
|
> Or if they want to pin a root public key to ensure some other CA doesn't issue a MITM certificate, go for it Please don't pin roots, as that makes it harder to distrust CAs, reducing the agility of the WebPKI. See the Symantec distrust for a painful example. Chrome and Firefox will be introducing term limits on roots in the near future, which will hopefully help to discourage this harmful practice. |
|
So what would be the recommended way to protect against government MitM by using some obscure CA?