Re: StartEncrypt considered harmful today

2016-07-01 Thread Christiaan Ottow
> On 30 Jun 2016, at 23:10, Andrew Ayer <a...@andrewayer.name> wrote: > > On Thu, 30 Jun 2016 22:36:19 +0200 > Christiaan Ottow <cot...@computest.nl> wrote: > >> We acquired certificates for a private domain (and some subdomains) >> of the tester in q

Re: StartEncrypt considered harmful today

2016-06-30 Thread Christiaan Ottow
On 30 Jun 2016, at 22:00, Andrew Ayer <a...@andrewayer.name> wrote: > > On Thu, 30 Jun 2016 15:54:02 -0400 > Jonathan Rudenberg <jonat...@titanous.com <mailto:jonat...@titanous.com>> > wrote: > >> >>> On Jun 30, 2016, at 15:44,

Re: StartEncrypt considered harmful today

2016-06-30 Thread Christiaan Ottow
ificates we had issuedto us as proof of concept (only for our own domains), were not revoked and we don't see them in the CT logs. However, we informed StartCom that we had only issued certificates for domains under our control, so I can imagine no red flags were raised by their helpdesk. Kind