Hi, I think we should not include CAcert (by default) until they can follow the rules mozilla (and others) require CAs to follow, and it's clear they do not follow those rules. For example the certificate for www.cacert.org has several issues.
Kurt -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org