Or can one install an arbitrary CA and limit it to `*.example.com`?
Or can one install an arbitrary CA and limit it to `*.example.com`?
1. Make CA #1 2. Make CA #2, have CA #1 sign (a certificate for) this CA with a constraint saying it is valid only for DNS names in example.com and nothing else 3. Destroy CA #1 irrevocably 4. Trust CA #1 in your browser or other relying party software 5. You can now use CA #2 to issue with your constraint.
If you care only about specific web browsers, you can modify the browser software (this is practical for Firefox and to some extent Chromium) to alter its built-in trust semantics to give you chosen CA different constraints. Firefox ships with constraints for a handful of CAs which, in Mozilla's opinion, can be afforded such limited trust so you can model your changes on how that works. https://wiki.mozilla.org/CA/Additional_Trust_Changes
HTTP/3 can be for people/applications that value what is has to offer, and can largely be ignored otherwise.