Hacker News new | ask | show | jobs
by direwolf20 135 days ago
The correct translation is that everyone in WebPKI only wants the responsibility of running the Web PKI and not the Everything PKI.
2 comments

> The correct translation is that everyone in WebPKI only wants the responsibility of running the Web PKI and not the Everything PKI.

The title of the current (2.2.2) CAB standard is "Baseline Requirements for the Issuance and Management of Publicly‐Trusted TLS Server Certificates":

* https://cabforum.org/working-groups/server/baseline-requirem...

§1.3, "PKI Participants", states:

> The CA/Browser Forum is a voluntary organization of Certification Authorities and suppliers of Internet browser and other relying‐party software applications.

IMHO "other relying-party software applications" can include XMPP servers (also perhaps SMTP, IMAP, FTPS, NNTP, etc).

If Google/Chrome doesn't want to allow it, good for them. But why do they get to dictate what others do?

The correct translation is that Google only wants the Google PKI and not the Everything PKI.