It gets worse. ICP-Brasil, the AC mentioned in the bug reports, the the government run agency responsible for all things related to digital signatures. Digitally signing a contract, a deed, accessing tax returns…
The problem here isn't really that one mis-issued certificate, but rather the general problematic behavior of that CA reported in TFA.
If a CA can be convinced to issue a server certificate for google.com, would you feel very comfortable trusting their contract/deed/... signing certificates?
justinclift|1 year ago
layer8|1 year ago
lxgr|1 year ago
If a CA can be convinced to issue a server certificate for google.com, would you feel very comfortable trusting their contract/deed/... signing certificates?
perching_aix|1 year ago
bawolff|1 year ago