> we just trust these organizations to not deploy wildcard malicious certificates.
Don't we have transparency logs to check that now?
Don't we have transparency logs to check that now?
(in memory of Douglas Adams)
It's this one. https://bugzilla.mozilla.org/show_bug.cgi?id=505521
RunSet™: Install everything everywhere all at once.
[Donate]
They don't actually go check and compare the embedded SCT with what is in the logs. It would be incredibly slow to load the site if they did that.
It's not clear to me how you know who asked for the certificate in the log. Do you somehow compile the private keys of all entities that are allowed to request certificates and compare that to the CTL?