Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just to be clear, this is important because eventually Let's Encrypt wants to no longer have to cross-sign their certificates for them to be considered valid.

For that to happen they have to be added as a trusted CA in most major platforms (and Firefox which has their own CA store for some reason).



> (and Firefox which has their own CA store for some reason).

Firefox has it's own CA store because it's built for all 3 major (desktop) platforms. OSX and Windows have their own but Linux does not and uses Mozilla's.


More importantly, Firefox has its own CA store because it was derived from Netscape, which had its own because they came up with the whole SSL thing way back. The subsystem is still called NSS, even though there's been backbend changes (pkix).


Does Chrome provide its own CA store on Linux? It's also built for all 3 major desktop platforms but uses the OSX and Windows stores.


They just use a copy of Mozilla's one on Linux. Of course, distro packages of Chromium if they use the system NSS library may well use some system CA store.


Would be interesting if there's a roadmap for who's left to be added to.

I saw their aim is to migrate to their own root CA by the end of the year, but i wonder if this is realistically feasible?


We have also applied to the Apple, Microsoft, Oracle, Blackberry, and Google root programs.

We had hoped to be accepted by all major programs by the end of this year, but even if that happened it would still take years for our root to sufficiently propagate.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: