I see that LE has their intermediate cert cross-signed with IdenTrust so the major browsers will trust it. Would it be possible for LE to cross-sign cacert.org’s intermediate so it would be trusted as well? In other words, one non-profit organization helping another non-profit organization.
I don’t think that is plausible, because CACert allows wildcard certificates, while LE has said that they possibly won’t allow it for now. Also, CACert doesn’t have enough random bytes at the SerialNumber of the certificate. @jsha What’s your opinion on this?
Hi @alspaughb, Let’s Encrypt is not able to do this; our intermediate certificate issued by IdenTrust does not allow us to issue further downstream intermediate certificates. If you look at our intermediate cert, it contains
good question. also I think IdenTrust wouldnt have liked it if LE just corss-signed CACert.
but LE could use its own root to cross sign CACert even thought it has yet no efect on browser trust.