logoalt Hacker News

throw0101dtoday at 7:02 PM2 repliesview on HN

> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?

How's the support for X.509 "Name Constraints" these days:

* https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1....

Would restricting it to only dot-ir domains be a mitigation?

* https://en.wikipedia.org/wiki/.ir


Replies

Hizonnertoday at 7:05 PM

Why would the Iranian government put such a constraint in its own root certificate?

show 1 reply
AtNightWeCodetoday at 7:10 PM

The whole point with a CA is that you have a neutral third party participant. Kinda broken no matter how you look at it. Especially in this case.