|
|
|
|
|
by fc417fc802
82 days ago
|
|
So how does that work with middleboxes? Corporate isn't about to forgo egress security (nor should they). I don't currently MITM my LAN but my general attitude is that if something won't accept my own root certificate from the store then it's broken, disrespecting my rights, and I want nothing to do with it. Trust decisions are up to me, not some third party. |
|
The default should be to reject certificates which aren't being logged, and if you as a user or corporation have a reason to use private certificates, you just configure your computer to do that. Which fully protects against the risk of normal CAs signing fraudulent certificates.