If you are of the types who like tinkering, here is a way to restrict CA certificates in your Fedora on specific domains. Currently limited to gnutls applications. http://nmav.gnutls.org/2016/06/restricting-scope-of-ca-certificates.html regards, Nikos -- security mailing list security@xxxxxxxxxxxxxxxxxxxxxxx https://lists.fedoraproject.org/admin/lists/security@xxxxxxxxxxxxxxxxxxxxxxx