RejectedCAs.md (888B)
- # Rejected Certificate Authorities
- ## GlobalSign
- ### Proprietary verification
- Even post-ACME, they still support non-standard verifications, in fact in September 2014 they added the non-standard ability to set custom emails via DNS TXT records: <https://support.globalsign.com/ssl/ssl-certificates-life-cycle/using-dns-txt-records-specifying-domain-approver-emails>
- ### Custom CAs
- - <https://www.globalsign.com/en/custom-ca-private-pki> seems to allow man-in-the-middle ("SSL/TLS Inspection/Decryption") which should only be done with a special non-trusted certificates.
- - Cross-signs other CAs, which while interesting for allowing new CA, ultimately means having to trust all the cross-signed CAs
- ## ZeroSSL
- This is a sockpuppet of COMODO which has been involved in numerous controversies: <https://en.wikipedia.org/wiki/Comodo_Cybersecurity>
- ## Sectigo
- Re-branding of COMODO.