Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From a policy standpoint, including AKI will still be a MUST, as will SKIs in CA certificates. Only in end-entity certificates will SKI be NOT RECOMMENDED.

That said, they all suffer from the same problem - they look like they're derived from the public key, but there's no guarantee of this. Their only use is as an opaque identifier for looking up the issuer of a certificate, and only some certificate validators use them (e.g. Microsoft's); other validators (e.g. Mozilla's) ignore AKI/SKI entirely and just look up issuers by subject name, which works completely fine, suggesting that AKI/SKI are unnecessary.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: