Comment on Entrust Certificate DistrustparentComments−1oooqooq2yafter you sold a .gov then any discussion about not supporting your root means denying users access to that .gov service.−e63f67dd-065b2yMany government websites use Entrust, and that didn’t stop this from happening. So I don’t think that this is a good theory.−lokar2yCA roots are not connected to tlds−devrand2yThey’re saying that once you’ve sold certs to governments, distrusting that root will deny people access to government resources. They’re merely using “.gov” as a proxy for “some government”.Also roots can be TLD constrained, typically to ccTLD(s).−lokar2yBut they are very carefully not breaking anyone. If you have an entrust cert it will keep working, you can even renew it with them.
Comments
after you sold a .gov then any discussion about not supporting your root means denying users access to that .gov service.
Many government websites use Entrust, and that didn’t stop this from happening. So I don’t think that this is a good theory.
CA roots are not connected to tlds
They’re saying that once you’ve sold certs to governments, distrusting that root will deny people access to government resources. They’re merely using “.gov” as a proxy for “some government”.
Also roots can be TLD constrained, typically to ccTLD(s).
But they are very carefully not breaking anyone. If you have an entrust cert it will keep working, you can even renew it with them.