• TCB13@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    8 months ago

    The proposed legislation says that browsers “can’t do adicional validations on the certificates from the CA” (more or less this wording) meaning a simple check CAA DNS check from a browser would be against said legislation.

    • SheeEttin@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 months ago

      Does a “warning, cert issued by a government agency” count as additional validation?

      Or maybe everyone is going to use cert pinning now. Or Firefox is going to stop trusting all CAs and make you verify each CA yourself. Which is a terrible idea for the average user.

      • TCB13@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 months ago

        Does a “warning, cert issued by a government agency” count as additional validation?

        From what I gather they can’t do that either.

        Or maybe everyone is going to use cert pinning now.

        Same as above. This would be effectively “adicional validations on the certificates”.

        Or Firefox is going to stop trusting all CAs and make you verify each CA yourself. Which is a terrible idea for the average user.

        Would be legal but annoying. Bet they would legislate to force their CAs / be exempt from that user verification.