|
|
|
|
|
by tonymet
342 days ago
|
|
Is any amateur or professional auditing done on the CA system? Something akin to amateur radio auditing? Consumers and publishers take certificates and certs for granted. I see many broken certs, or brands using the wrong certs and domains for their services. SSL/TLS has done well to prevent eavesdropping, but it hasn't done well to establish trust and identity. |
|
At the same time, it sounds like the issues you describe aren’t CA/issuance issues, but rather, simple misconfigurations. Those aren’t incidents for the ecosystem, although definitely can be disruptive to the site, but I also wouldn’t expect them to call trust or identity into disrepute. That’d be like arguing my drivers license is invalid if I handed you my passport; giving you the wrong doc doesn’t invalidate the claims of either, just doesn’t address your need.