|
|
|
|
|
by plagiat0r
124 days ago
|
|
All I'm saying is that publishing final certificate is not required for the process, so just assuming it will be there is premature. User may end up putting precert on his https server and find the hard way. Happy to see LE publish both, but others do not. Here is an example: https://crt.sh/?id=17293798014 Your won't find final certificate from digicert/globalsign in the CT logs. Unless the owner publish it himself, API is opened for submission I think for everybody. |
|
I'm not disputing that there could be a world where you're correct, but, it's not this world, which is why I even made that comment. That doesn't make relying on the logs for this a brilliant idea, it's just an observation that in fact it could work.