Suppose a leaf node creates a certificate for a different domain, acting as a CA.
Do most popular frameworks, or SSL chain validation tools verify the constraints? Are there any I should be concerned with, and remove from my production environment?
Should I be concerned with CA's issuing certificates without basic constraints?
How can I protect my website (as a server operator), and my web browsing session (as a consumer) from certificates generated by leaf nodes, or improperly configured CAs?