[SSL Observatory] SSL CA compromise in the wild

Peter Gutmann pgut001 at cs.auckland.ac.nz
Thu Mar 24 01:33:19 PDT 2011


Seth David Schoen <schoen at eff.org> writes:

>The OCSP design presumably should require checking all the way up the cert
>chain, but I guess people felt that that would add too much latency.

Walking the chain won't make any difference, since it leads to a trusted root
CA.

Peter.



More information about the Observatory mailing list