TLS certificate management on Android
TLS certificate management on Android
Posted Mar 6, 2016 20:35 UTC (Sun) by tialaramex (subscriber, #21167)In reply to: TLS certificate management on Android by Cyberax
Parent article: TLS certificate management on Android
The "delegation" pipe dream is just that. Today, in 2016, there are brand new SSL certificates being minted that still don't use the correct method to indicate which DNS names the certificate is for, but instead rely on bug compatibility between major browsers to "get away" with continuing to do things the way they did with Netscape Navigator (remember that?)
Huge parts of the x509 certificate spec are written off as unsuitable for any purpose for years and probably decades to come because either incompetently written software was allowed to spread into the wild that relies on nobody using that part of the spec, or, perhaps even worse, Certification Authorities (who are supposed to be experts) signed certs that mis-used those parts of the spec and which don't expire for many years. Delegation is one of those parts. I thought it sounded like a brilliant idea when I first heard about it, but it can't work for probably a decade or more after we get CAs to treat it as real, and we're nowhere near even that. Nobody wants to fight with them about something we probably will never get to see any use out of anyway.
