einsteinx2 4 days ago

Repeating it doesn’t make it any more true. Cert providers publish their root certs, you pin those root certs, zero problems.

2
nickf 3 days ago

Then the CA goes away, like Entrust. Huge problems. I speak (sadly) from experience.

Plasmoid 3 days ago

They rotate those often enough.