On 3/18/22, 3:46 PM, "Mathew, Sunil" <smathew at hbs.edu> wrote: > In this case it is dynamically loaded from a url. This is helpful when certificates get rotated often. And also a prime attack source. I never trust vendor metadata, and they botch key rollovers as often as they'd get it right so I lose nothing in the process. -- Scott