Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A Chrome update was needed because the constraint was applied retrospectively. A name constraint is usually an X.509 extension that is included in the certificate.


[deleted]


> Every time you visit a page the OS/browser doesn't go up the entire chain of trust and check for constraints.

Oh, certainly they do. Name constraints work just like that: https://tools.ietf.org/html/rfc5280#section-4.2.1.10

So does Extended Key Usage in practice, although it's not defined that way.

There are some platforms where name constraints aren't implemented, but CAPI (Windows) certainly does implement it and I believe that NSS does also.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: