Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was not aware of this option. However, it seems to be operating out of China. How does that affect security and availability in the long run?


It doesn't affect security, they're already in browsers' trust stores. It does affect availability, but only because (the last time I checked) WoSign's OCSP responders operated from China only. To address network latency issues with your users located far away, make sure you have OCSP stapling configured on your servers.


Maybe availability but as long as you generate the private key part and paste your CSR on the website they can at worst revoke your certificate. So from a security perspective they're not worse then the others.


You already trust them. They're in all the major browser trust stores




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: