Hacker News new | past | comments | ask | show | jobs | submit login

They're cross-signed by startcom.



Windows actually trusts 5 WoSign roots by default, regardless of the StartCom cross-signing.

Friendly names: WoSign - WoSign 1999 - WoSign ECC - WoSign G2 - WoSign China


Given StartCom's bad behavior, you're probably better off marking them untrusted too.


I'm not familiar with this. Does it mean that if you trust StartCom you have to trust WoSign?


No, you can explicitly install the WoSign certificate into the "Untrusted Certificates" chain.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: