Post #3087445
2026-02-27 13:50 UTC
@agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange It also opens the door for using .arpa names as a way to send TLS SNI for IP address certs with less risk (which is a problem and not-well-specified today), and removes some of the edge cases there for the RFC that already does this.
Replies (1)
-
@agowa338@chaos.social 2026-02-27 13:53
@nygren@hachyderm.io @InfobloxThreatIntel@infosec.exchange After the last fallout with "serverAuth + clientAuth" being disallowed I'm not even sure anymore if these changes are really pushed by the CA/Browser Forum or just yet another #Google thing that they just c'n'p-ed after google did it in the google chrome certificate authority policy...