Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

These domains belong to someone. Someone who likely hasn't agreed. It's deeply troubling when a CA says: "We'll just issue some test certs for domains that sound like we could use them for testing - no matter whom they belong to and if they agree to that." It's quite simple: Don't issue certs unless the owner of that domain has asked you for it.

But if you look closer at Andrew's mail: There were a bunch of other certs for all kinds of domains.



Especially when we have TLDs for this purpose (.test and .invalid), it's just plain sloppy.


CAs would not be allowed to use those TLDs under the current rules. They have two options for testing:

1. Use domains they own.

2. Use a testing environment that doesn't issue publicly-trusted certificates.


> * it's just plain sloppy*

Sloppy is an oopsy. This is negligence.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: