I was laid off. Twice, in fact. Both times, I was unemployed for ~6 months. My wife and I had two small children (under 4) at the time, a mortgage, blah, blah.

Our choices enabled us to weather the bad times without them being catastrophic. We didn't buy the biggest house we could possibly afford, despite pressure from our lender and realtor to upsize. And this was in 2003, in the heyday long before the housing bubble exploded. We didn't buy new cars every year or two. We made most meals at home. We did travel the world a bit, but we prioritized savings, of both the long-term retirement and rainy-day varieties.

So when life threw its inevitable curveballs our way, we endured...and despite the snarky presumptions of some asshats here, we didn't run to our parents for shelter.

As I said, we *created* our circumstances, just as everyone does...either through preparation or lack thereof. That doesn't mean I'm without empathy, though. I'm about as tree-hugging crunchy leftist hippie as they come where social/humanitarian issues are concerned. But I have no patience with bullshit puling about victimhood and powerlessness in these types of employment scenarios. If you're a slave to debt or salary, it's because you put the yoke on your own shoulders.

I don't live beyond my means, and that includes having savings. I wouldn't worry about those bills you mention because they'll get paid in the interim. If they'd worry you, I posit that perhaps you're the one who needs to take stock of his own financial situation before judging another for being willing to live out his convictions.

The only reason you'd need a Verisign intermediate CA is if you want to be able to hit the vast majority of clients as configured out-of-the-box, without your certs pushed by group policy or whatever. Nobody involved seems to have a remotely good explanation of why Bluecoat has one; or what legitimate purposes it could possibly serve that couldn't be served by a vastly less dangerous toy.

The reason is simple: most customers of these devices prefer to implement them in transparent proxy mode, which requires no endpoint device (browser, etc.) configuration, no pushing of internal certs, etc. Browsers are talking on 80/443 happily unaware that their traffic is being proxied, and the SSL server certs being presented by Google or Facebook or their bank are not actually certs from those servers...they're Blue Coat's imposter certificates, generated on-demand.

I will tell you what Fedora version I plan to skip: whatever initially switches us to Wayland. That will be a guaranteed shit-show, and a good call to avoid upgrading for a few months. But 24 is solid methinks.

Thanks! Yeah, I'll likely sit that one out as well. X works just fine for what I do.

"The voters have spoken, the bastards..." -- unknown