I personally have a whitelist policy for CAs. Custom hook for the ca-certificates ebuild and manual review of the NSS certstore (Chrome/etc)
-
-
Replying to @marcan42
how often do you catch CAs you don't trust being used?
1 reply 0 retweets 0 likes
Replying to @femmetasm
Quite often, but 99% of the time I don't care (no login, information-only sites, etc.). I've gotten good at typing "badidea".
5:56 AM - 29 Aug 2016
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.