Hacker News new | ask | show | jobs
by orf 492 days ago
None of this makes any sense.

A lack of CRL doesn’t make TLS insecure.

A root doesn’t produce “self-signed certificates”. That especially doesn’t make any sense. What do you think the “self” references in “self-signed” certificate?

Add the root to your trust store, if you trust it, and you’re done.

What’s more concerning is someone working on (assumingly) secure, sensitive, air-gapped networks knows this little about TLS?