There is a public exception process to handle SHA1 certificates, and for the rest, they get special certificates of old root certificates that are only on older devices.
Obviously, all these options are not available to anyone except a handful of large companies.
Comments
There is a public exception process to handle SHA1 certificates, and for the rest, they get special certificates of old root certificates that are only on older devices.
Obviously, all these options are not available to anyone except a handful of large companies.
That's at best off topic again. We're discussing the actions and trustworthyness of a currently trusted root CA here.
Edit: The exception processes also do not involve fraudulently backdating anything. Which is kind of a big deal when you are in the trust business.