Hacker News new | ask | show | jobs
by thrtythreeforty 819 days ago
I'm curious: What's the defense mechanism for a dodgy CA not publishing a CT log entry for the misused domain?
1 comments

A CT-honoring client should reject an end-entity certificate that isn't accompanied by a SCT. In other words: a dodgy CA that skips CT to avoid disclosure of their mis-issued certificate should be unable to convince any CT-honoring client to accept that certificate.