Elektrine lite

← Feed

@nygren@hachyderm.io

Post #3087445

2026-02-27 13:50 UTC

@agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange It also opens the door for using .arpa names as a way to send TLS SNI for IP address certs with less risk (which is a problem and not-well-specified today), and removes some of the edge cases there for the RFC that already does this.

Replies (1)

  • @agowa338@chaos.social 2026-02-27 13:53

    @nygren@hachyderm.io @InfobloxThreatIntel@infosec.exchange After the last fallout with "serverAuth + clientAuth" being disallowed I'm not even sure anymore if these changes are really pushed by the CA/Browser Forum or just yet another #Google thing that they just c'n'p-ed after google did it in the google chrome certificate authority policy...

    Open ##3087446