The Register® — Biting the hand that feeds IT

Feeds

* Posts by pdw

1 post • joined Saturday 17th December 2011 08:12 GMT

pdw
WTF?

Shurely some mistake

> Under the current SSL system, CAs get to log each visit an IP address makes to an HTTPS page protected by one of their certificates.

What?!

The client knows the root cert (installed in O/S, browser, whatever) and the server has a series of signed certs linking back to it. There is no connection to the CA.