Hacker News new | ask | show | jobs
by geofft 4092 days ago
The first part isn't super reliable. Historically, CAs have just let you put whatever you want there and only enforced the common name. They're supposed to be cleaning up their act (at least for recently-issued certs), but I'd still only trust it for EV certs.

The rest is all valid. (Unless you assume that the hack also hacked DNS, which is plausible but unlikely.)

1 comments

Do you have any links regarding that? Regardless, some/most trusted CAs include the OID 2.23.140.1.2.2 when a certificate is OV validated per CA/B guidelines, so you could just look for that.