Hacker News new | ask | show | jobs
by throw0101a 133 days ago
> […] there are a lot of reasons why browsers need to care about whether CAs are issuing insecure certificates to XMPP or SMTP servers (or credit card machines)

Why does having the clientAuth capability make a certificate "insecure"?