Hacker News new | past | comments | ask | show | jobs | submit login
Should you trust a root CA that couldn't keep track of it's own keys? (twitter.com/taviso)
10 points by tptacek on June 8, 2011 | hide | past | favorite | 1 comment



Just to be clear, this is presumably (judging by the filename) the private key associated with the SSL cert for https://www.certigna.fr/, rather than the CA private key (which would hopefully be in a HSM), correct?

Not that this make this look any better better, but I think some may be confused that this is a compromise of the CA itself, rather than evidence of poor key management/security practices.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: