logoalt Hacker News

lxgryesterday at 9:33 PM1 replyview on HN

What "backdoor" would Let's Encrypt even implement? That's not how a CA works.

They might be compelled to issue a certificate to an unauthorized (by browser PKI policies, not local law) entity, but that would be very conspicuous due to Certificate Transparency.


Replies

firefaxyesterday at 10:20 PM

I suspect any "backdoor" would be inserted at the protocol level. See https://web.archive.org/web/20130918135152/http://www.thegua...

show 1 reply