|
|
|
|
|
by mmsc
134 days ago
|
|
No. HTTPS certificates are being abused for non-https purposes. CAs want to sell certificates for everything under the sun, and want to force those in the ecosystem to support their business, even though https certificates are not designed to be used for other things (mail servers for example). If CAs don't want hostility from browser companies for using https certificate for non-http/browser applications, they should build their own thing. |
|
I put "HTTPS certificates" in quotes in this comment because it is not a technical term defined anywhere, just a concept that "these certificates should only be used for HTTPS". The core specifications talk about "TLS servers" and "TLS clients".