#1207: Einstein toolkit sites with invalid security certificates --------------------------------------+------------------------------------- Reporter: hinder | Owner: Type: enhancement | Status: new Priority: minor | Milestone: Component: EinsteinToolkit website | Version: Resolution: | Keywords: --------------------------------------+-------------------------------------
Comment (by knarf):
I would then leave this "wontfix". Old certificate lists on clients are not anything we can tackle from a server side. This has to be fixed by the respective admin. And no - we don't get to choose our certificate authority, at least not through LSU. Plus, with something like heartbleed in mind not even doing that would be "safe".
When you deal with certificates the client has to deal with the trust themselves, otherwise there is no point in doing it.