Hacker News new | past | comments | ask | show | jobs | submit login

I'm surprised and a bit skeptical that every CA (except for one) randomizes serial numbers without it being published in a standard or guidance document somewhere. Best practice usually has something worse than a (n - 1) distribution.



was the "one" in those articles? I didn't see. Anyway, who do you trust to buy certs from? I need to get a new one soon and would like recommendations.


What's slightly ironic is trust doesn't matter for the buyer.

As long as you purchase your certificate from a CA well placed in the major browser vendors, you're good to go.

Edit: Here's a list of Mozilla's included certificates: http://www.mozilla.org/projects/security/certs/included/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: