Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

adding a local CA means you can middleman anything you want to, seems like something that should be difficult to do, to me.


Name constraints are a thing. Local CA should be constrained to signing only local names (roughly matching dhcp domain-name/domain-search options).


Name constraints are not universally supported in browsers sadly.


And this should be fixed. Name constraints would be incredibly useful for a number of things, if only they were supported.


I believe Apple is the holdout in this case, meaning Safari and Chrome on MacOS don't support it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: