Folks might find this article, *and the things it links to* as useful starting points. https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/ I am not sure if general discussion of CA trust issues is appropriate for openssl-users. -- Senior Architect, Akamai Technologies Member, OpenSSL Dev Team IM: richsalz at jabber.at Twitter: RichSalz -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20161026/0635ccdd/attachment.html>