Why are there intermediary CA's? They seem to hold the same power as a CA but little of the responsibility.
It would be similar to allowing a secondary DNS provider to hold primary powers. I could start big-huge-secondary-dns-provider.example.com and edit my zones locally. The master could pick them up, and serve them out.
DNS was not made that way, so why is the chain of command in a CA made that way?
* I understand you can edit a secondary and if people are using it as a recursive DNS provider, you will in fact get back "lame" data, but that is almost never the case where a secondary is used as recessive recursive. At least not in any of the setups I have seen, deployed, or administered. [edit: spelling]
It would be similar to allowing a secondary DNS provider to hold primary powers. I could start big-huge-secondary-dns-provider.example.com and edit my zones locally. The master could pick them up, and serve them out.
DNS was not made that way, so why is the chain of command in a CA made that way?
* I understand you can edit a secondary and if people are using it as a recursive DNS provider, you will in fact get back "lame" data, but that is almost never the case where a secondary is used as recessive recursive. At least not in any of the setups I have seen, deployed, or administered. [edit: spelling]