#1061: Certificate failure --------------------------------------+------------------------------------- Reporter: eschnett | Owner: Type: enhancement | Status: reopened Priority: minor | Milestone: Component: EinsteinToolkit website | Version: Resolution: | Keywords: --------------------------------------+-------------------------------------
Comment (by hinder):
We need to evaluate the end-to-end consequences of what we do, rather than applying a narrow definition of who is right and who is wrong. If some very popular OS has an old list of trusted root certificates, and we require a new one, then we are broken on that OS, and it doesn't really matter whose fault it is. When you buy an SSL certificate, does it come with some indication of the number of widely-deployed systems which it will work with? If you buy a cheaper certificate, will it work with fewer systems? I'm wondering if there is a financial aspect to this.