Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure, if I see an EV cert, I trust that cert slightly more. However, unless I expect an EV cert and happen to check, there is no downside to having a DV cert.

If you are going to pin your apps to a CA, you have quite a few other options. For example, you could cross-sign all your certs by your own root CA cert and pin to that in addition to pinning to the other CA. At this point, you don't need to trust the CA as long as you trust your own root cert.



I didn’t make any reference to any visual/user benefits/trust from EV certs.

If you’re going to do cross-signing, then you do need to essentially operate your own root program - assuming you want to keep your own root secure. You’ll also then presumably need to serve an additional cert (or two, if you’re keeping your own root offline) in the intermediate chain so it can be validated by the client.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: