Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One of them is tied to a root CA and works on all devices. The other is not, and does not.


Certificates issued by Let's Encrypt are cross-signed by IdenTrust and are trusted by all major browsers[1]. This is just about their own root certificate. Being cross-signed by an existing, trusted CA is a common practice for new CAs, as it would take years for the CA to become usable in practice otherwise.

[1]: https://community.letsencrypt.org/t/which-browsers-and-opera...


LE is tied to a root CA (IdenTrust's). The support is almost universal, with only obsolete OSs not trusting them: https://community.letsencrypt.org/t/which-browsers-and-opera...


Despite a fairly large number of users on XP still (2.5% of total users on some sites I manage), I'll give you that it works on non-obsolete OS browsers. However, those are not the only pieces in the world of security.

Java, for example, only started support as recently as 3 weeks ago (2016-07-19)


XP is supported. There was an issue due to some schannel bug in XP choking on the issuer certificate, but that was fixed earlier this year.


Lot's of people care about and make their money off users with "obsolete OS's and browsers".


And they're just as likely to have problems with any other CA.


Including HN / ycombinator?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: