Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
possiblylinux127@lemmy.zip 3 hours agoMaybe I’m mistaken but aren’t the logs cryptography verifiable? (As in you can’t create a rouge cert without it creating a trace)
WhyJiffie@sh.itjust.works 3 hours ago
apparently certs can have a cryptographic proof of having been included in the CT logs. but what do browsers do if the letsencrypt cert has no such proof?
needanke@feddit.org 2 hours ago
You can test that on this site:
no-sct.badssl.com