On Tue, December 22, 2015 01:15, Christoph Anton Mitterer wrote: > Control: tags -1 + wontfix > > On Mon, 2015-12-21 at 10:23 +0100, Thijs Kinkhorst wrote: >> Such polarizing comments are not welcome and do not serve to improve >> Debian. I'm closing the bug now. > I'm afraid when factual issues are considered polarising. > Well serving examples for such CA's should include e.g. CNNIC or > TURKTRUST (yeah, of course, it was an "accident" that they created > forged google.com certs and placed them in the wild o.O)
Your statement was: "Given that Mozilla includes for money basically any CA nowadays, even such which are inherently untrustworthy" As you've clarified, apparently your opinion is that audits alone are not reliable to determine worthiness of inclusion and you wish to see full certificate subjects to better make your own choice of which CA's to trust. I personally doubt whether the C= field is a reliable indicator of that, but that is up to you. By not formulating it this way, but instead choosing to use the statement above 'will do (basically) anything for money', you choose to put focus explicitly on the fact that it costs money and highly suggest a moral judgment of their operation. It is really not a matter of language difference that you choose to play the money card. It doesn't help to add the claim that some CA's are 'inherently' untrustworthy in the same sentence, which further reinforces the connection between accepting money and doing something morally rejectable. It's clear to me that you're strongly opinionated about the workings of the CA system; your concerns also surface again in your followup. However, I believe the BTS is not the right platform for that. As for your request, I will reopen it and we can consider the possibilities of it. I do hope that in the future you can show some restraint in your approach. Cheers, Thijs

