#webpki — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #webpki, aggregated by home.social.
-
⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁
"We have been made aware of a potential incident and are shutting down all issuance."
May 8, 2026 18:37 UTC
https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
#letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure
-
⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁
"We have been made aware of a potential incident and are shutting down all issuance."
May 8, 2026 18:37 UTC
https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
#letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure
-
⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁
"We have been made aware of a potential incident and are shutting down all issuance."
May 8, 2026 18:37 UTC
https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
#letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure
-
⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁
"We have been made aware of a potential incident and are shutting down all issuance."
May 8, 2026 18:37 UTC
https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
#letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure
-
⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁
"We have been made aware of a potential incident and are shutting down all issuance."
May 8, 2026 18:37 UTC
https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
#letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure
-
https://www.europesays.com/at/139707/ Vorfall bei DigiCert: Malware-Autoren klauten Zertifikate #AT #Austria #Digicert #IT #Malware #Österreich #PKI #Science #Science&Technology #Security #Technik #Technology #WebPKI #Wissenschaft #Wissenschaft&Technik
-
🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
https://blog.brycekerley.net/2026/03/08/webpki-and-you.html #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated -
🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
https://blog.brycekerley.net/2026/03/08/webpki-and-you.html #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated -
🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
https://blog.brycekerley.net/2026/03/08/webpki-and-you.html #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated -
🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
https://blog.brycekerley.net/2026/03/08/webpki-and-you.html #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated -
March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029.
Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you.
https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI
-
March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029.
Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you.
https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI
-
CertKit Agent 1.6: RRAS support, deploy windows, and agent locking.
Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized.
-
CertKit Agent 1.6: RRAS support, deploy windows, and agent locking.
Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized.
-
#Heise:
"
"Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderemEine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
"
https://www.heise.de/news/Passwort-Folge-40-Probleme-mit-Widerrufen-Verbindungsabbruechen-und-anderem-10632694.htmlmp3: https://audio.podigee-cdn.net/2098722-m-7a844de5c304b67bf99d2ee327d88425.mp3
10.9.2025
Aaaa.. MS..
#CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat
-
#Heise:
"
"Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderemEine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
"
https://www.heise.de/news/Passwort-Folge-40-Probleme-mit-Widerrufen-Verbindungsabbruechen-und-anderem-10632694.htmlmp3: https://audio.podigee-cdn.net/2098722-m-7a844de5c304b67bf99d2ee327d88425.mp3
10.9.2025
Aaaa.. MS..
#CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat
-
#Heise:
"
"Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderemEine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
"
https://www.heise.de/news/Passwort-Folge-40-Probleme-mit-Widerrufen-Verbindungsabbruechen-und-anderem-10632694.htmlmp3: https://audio.podigee-cdn.net/2098722-m-7a844de5c304b67bf99d2ee327d88425.mp3
10.9.2025
Aaaa.. MS..
#CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat
-
#Heise:
"
"Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderemEine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
"
https://www.heise.de/news/Passwort-Folge-40-Probleme-mit-Widerrufen-Verbindungsabbruechen-und-anderem-10632694.htmlmp3: https://audio.podigee-cdn.net/2098722-m-7a844de5c304b67bf99d2ee327d88425.mp3
10.9.2025
Aaaa.. MS..
#CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat
-
#Heise:
"
"Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderemEine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
"
https://www.heise.de/news/Passwort-Folge-40-Probleme-mit-Widerrufen-Verbindungsabbruechen-und-anderem-10632694.htmlmp3: https://audio.podigee-cdn.net/2098722-m-7a844de5c304b67bf99d2ee327d88425.mp3
10.9.2025
Aaaa.. MS..
#CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat
-
CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/
-
CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/
-
CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/
-
CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/
-
CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/
-
Within the #WebPKI, the "common name" is widely irrelevant afaik:
https://infosec.exchange/@pft/114745413874521644
So the question is: what are the circumstances that can pose a security risk if IP addresses are included in the CN field.
-
Firefox 136 looks poised to enforce Certificate Transparency.
It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.
While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.
Originally posted on
seirdy.one: See Original (POSSE). #Firefox #WebPKI -
Firefox 136 looks poised to enforce Certificate Transparency.
It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.
While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.
Originally posted on
seirdy.one: See Original (POSSE). #Firefox #WebPKI -
Firefox 136 looks poised to enforce Certificate Transparency.
It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.
While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.
Originally posted on
seirdy.one: See Original (POSSE). #Firefox #WebPKI -
Firefox 136 looks poised to enforce Certificate Transparency.
It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.
While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.
Originally posted on
seirdy.one: See Original (POSSE). #Firefox #WebPKI -
Firefox 136 looks poised to enforce Certificate Transparency.
It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.
While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.
Originally posted on
seirdy.one: See Original (POSSE). #Firefox #WebPKI -
New blog post: Post-OCSP certificate revocation in the Web PKI.
With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.
I think this is the most comprehensive current look at certificate revocation right now.
-
New blog post: Post-OCSP certificate revocation in the Web PKI.
With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.
I think this is the most comprehensive current look at certificate revocation right now.
-
New blog post: Post-OCSP certificate revocation in the Web PKI.
With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.
I think this is the most comprehensive current look at certificate revocation right now.
-
New blog post: Post-OCSP certificate revocation in the Web PKI.
With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.
I think this is the most comprehensive current look at certificate revocation right now.
-
New blog post: Post-OCSP certificate revocation in the Web PKI.
With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.
I think this is the most comprehensive current look at certificate revocation right now.
-
For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:
- OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
- CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
- Short-lived certs (inc. ACME-STAR, Delegated Credentials, and
notAfter)
Anything else I should cover?
-
For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:
- OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
- CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
- Short-lived certs (inc. ACME-STAR, Delegated Credentials, and
notAfter)
Anything else I should cover?
-
For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:
- OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
- CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
- Short-lived certs (inc. ACME-STAR, Delegated Credentials, and
notAfter)
Anything else I should cover?
-
For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:
- OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
- CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
- Short-lived certs (inc. ACME-STAR, Delegated Credentials, and
notAfter)
Anything else I should cover?
-
For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:
- OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
- CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
- Short-lived certs (inc. ACME-STAR, Delegated Credentials, and
notAfter)
Anything else I should cover?
-
OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.
-
OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.
-
OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.
-
OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.
-
OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.
-
Apropos of nothing, here's a fun question at the intersection of #linguistics and the #webpki. Given the following sentence:
"...has determined that using the FQDN in the Certificate is no longer legally permitted."
which of the following two things do you think is no longer legally permitted?