←back to thread

246 points nh2 | 1 comments | | HN request time: 0.244s | source
Show context
billpg ◴[] No.41912612[source]
Is "name constraints" new? I wanted to do something similar a decade or two ago and found I'd have to be trusted for all domains, which I wanted to avoid.
replies(2): >>41912756 #>>41915972 #
1. michaelt ◴[] No.41912756[source]
It's been around since ~2008 when rfc5280 was released.

But it's long been stuck in a cycle of "CAs won't issue name-constrained certificates because not all clients support it properly" and "Clients don't bother to support it properly because CAs won't issue name-constrained certificates"

And even if today's clients all support it properly - there will always be some users running ancient smart TVs and android phones that haven't received a software update in a decade.