Why would the Iranian government put such a constraint in its own root certificate?
I guess now would be a great time for browsers/OSes to ship a "trust this CA, but only for this TLD/list of domains" feature.
I guess now would be a great time for browsers/OSes to ship a "trust this CA, but only for this TLD/list of domains" feature.