I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?
I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?
That the U.S. government can arbitrarily take down websites by revoking certificates issued by let’s encrypt? How obvious can it be? I wondered the same thing as OP months ago. We need european alternatives. I think there are some, have some bookmarked somewhere.
Certificate revocation is a joke and has been for over a decade
Huh, FF on Android doesn’t care.
Most browsers don’t, hence my calling revocation a joke.
So many in this thread are up in arms about something the majority of browsers don’t care about and have actively ignored for as long as I can recall
Yeah, I was just surprised bc the page explicitly lauds FF for checking revocation.
It may only be the desktop version, most mobile browsers aren’t as feature complete as their desktop counterparts.
But, given Google ripped revocation checking out of chromium, I wouldn’t be surprised if they nerfed it in Android too…
Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.
Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I’m curious if they added his cert in directly again, or if the onion browser actually follows standards the os browser doesn’t.
Yes, but safari doesn’t even let me ignore the warning, it has a explanation in detail, and only allows closing the website.
You didn’t look hard enough. My router cert isn’t valid and I have to bypass the warning every time.
Maybe there’s a special case for local subnets?
Here’s what shows up for me (in portuguese):
Clicking on more details, only allows me to check the certificate:
Here’s the translated details:
Said certificate:
Edit: on the latest iOS version (27) btw.
Thanks for the proof! I stand corrected! I see basically the same but after the view link there is another think that bypasses it.
Must be difference between expired vs compromised cert.
And what if you need to get a new certificate?
You go to a different CA
That’s the question of this thread. Yes.
Aren’t we back at OP’s question?