They might've passed the WebTrust audit, but I'm still pretty worried about their security posture.<p>Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice <i>any</i> CA in the world can issue certificates for any domain.<p>Let's recap: It's 2015. They're using SHA-1 for <i>everything</i> (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes, but at least he hasn't won an election yet. Edit: he pledged to <i>if he wins</i>; we have a coalition government, nobody won last time, least of all us! <g>) It looks like they've messed up OSCP, so even their own cert doesn't pass. Oh, and RC4, TLS 1.0 only, check out their login server: <a href="https://www.ssllabs.com/ssltest/analyze.html?d=login.wosign.com" rel="nofollow">https://www.ssllabs.com/ssltest/analyze.html?d=login.wosign....</a> - let's put the (slightly) stronger ones at the end, everyone! Ugh.<p>Let's Encrypt will do it <i>properly</i>. Or Else™. ;)