logoalt Hacker News

bawolffyesterday at 10:11 PM3 repliesview on HN

Google didn't force lets encrypt to totally get out of the client cert business, they just decided it wasn't worth the effort anymore.


Replies

nickfyesterday at 10:45 PM

Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.

everfrustratedyesterday at 10:44 PM

Feel free to start your own non-profit to issue client certs signed by a public authority.

As LE says, most users of client certs are doing mtls and so self-signed is fine.

josephcsibleyesterday at 10:44 PM

> they just decided it wasn't worth the effort anymore

That seems disingenuous. Doesn't being in the client cert business now require a lot of extra effort that it didn't before, due entirely to Google's new rule?

show 1 reply