10. #RSAC
TLS Cer1ficates – the Bad
10
EV viola>ons
~6% of all EV cer>ficates (Netcra_)
Most don’t have a valid Subject Business Category (unlikely to cause usability
problems)
Thousands don’t provide EV treatment in Chrome (customer doesn’t benefit
from the extra cost of EV)
BR viola>ons
~3% of all cer>ficates found (Netcra_)
Most are policy viola>ons (CN must appear in SAN, invalid Subject State or
Country, etc.) unlikely to cause usability problems