Skip to content

Comment on Entrust Certificate Distrustparent

Comments

CA roots are not connected to tlds

They’re saying that once you’ve sold certs to governments, distrusting that root will deny people access to government resources. They’re merely using “.gov” as a proxy for “some government”.

Also roots can be TLD constrained, typically to ccTLD(s).

But they are very carefully not breaking anyone. If you have an entrust cert it will keep working, you can even renew it with them.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.