Hacker News new | ask | show | jobs
by mvanotti 4101 days ago
In the blog post it says that CNNIC issued the CA=TRUE on the basis that MCS H only use it for domains that they have registered.. Wouldn't it be better to just issue a CA cert with name constrains extensions?

Why do we have that extension if nobody uses it :( ?