On Mon, Apr 17, 2023 at 11:41 AM Robert Relyea <rrel...@redhat.com> wrote:

> I know of no public CA which issues SSL client auth certs (or what it
> would mean for a server to trust a public client auth cert).
>

Let's Encrypt issues roughly 3 million publicly trusted certificates per
day that contain the client authentication EKU [1].  Even the White House
has one [2]!

[1]
https://github.com/letsencrypt/boulder/blob/82c1763824bd55669465751d2a8453874f9fc149/issuance/issuance.go#L314-L322
[2] https://crt.sh/?id=9173426978
_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to