Skip to content

Comment on Entrust Certificate Distrustparent

Comments

after you sold a .gov then any discussion about not supporting your root means denying users access to that .gov service.

Many government websites use Entrust, and that didn’t stop this from happening. So I don’t think that this is a good theory.

CA roots are not connected to tlds

They’re saying that once you’ve sold certs to governments, distrusting that root will deny people access to government resources. They’re merely using “.gov” as a proxy for “some government”.

Also roots can be TLD constrained, typically to ccTLD(s).

But they are very carefully not breaking anyone. If you have an entrust cert it will keep working, you can even renew it with them.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.