Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?

 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: