* Ben Hutchings:

> According to
> <https://www.globalsign.com/certificate-authority-root-signing/>, any
> organisation may buy a secondary CA certificate signed by one of
> GlobalSign's root CA certificates.  These should therefore not be
> trusted by default.

This is actually true for many of the roots.

You should bring this up on the Mozilla lists, I think.


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to