[openssl-dev] [openssl.org #3621] Support legacy CA removal, ignore unnecessary intermediate CAs in SSL/TLS handshake by default

Salz, Rich via RT rt at openssl.org
Mon Dec 15 14:23:35 UTC 2014


> For what it's worth, I have tested the Alexa top 1 million servers with the -
> trusted_first option and haven't found a single server that looses its trusted
> status, on the other hand, good few percent of servers do gain it.

It's worth a great deal.  Thanks!  I love fact-based analysis. :)



More information about the openssl-dev mailing list