home.social

#webpki — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #webpki, aggregated by home.social.

fetched live
  1. ⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁

    "We have been made aware of a potential incident and are shutting down all issuance."

    May 8, 2026 18:37 UTC

    letsencrypt.status.io/pages/in

    #letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure

  2. ⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁

    "We have been made aware of a potential incident and are shutting down all issuance."

    May 8, 2026 18:37 UTC

    letsencrypt.status.io/pages/in

    #letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure

  3. ⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁

    "We have been made aware of a potential incident and are shutting down all issuance."

    May 8, 2026 18:37 UTC

    letsencrypt.status.io/pages/in

    #letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure

  4. ⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁

    "We have been made aware of a potential incident and are shutting down all issuance."

    May 8, 2026 18:37 UTC

    letsencrypt.status.io/pages/in

    #letsencrypt #tls #webpki #pki #browsers #security #privacy #selfhosting #cybersecurity #ITInfrastructure

  5. ⚠️ 𝗟𝗲𝘁'𝘀 𝗘𝗻𝗰𝗿𝘆𝗽𝘁: 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 𝗜𝘀𝘀𝘂𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗣𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁

    "We have been made aware of a potential incident and are shutting down all issuance."

    May 8, 2026 18:37 UTC

    letsencrypt.status.io/pages/in

  6. 🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦‍♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
    blog.brycekerley.net/2026/03/0 #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated

  7. 🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦‍♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
    blog.brycekerley.net/2026/03/0 #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated

  8. 🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦‍♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
    blog.brycekerley.net/2026/03/0 #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated

  9. 🔐 Wanna read about #WebPKI to feel smart? Well, this site boasts about #HTTPS while rocking an expired cert. 🤦‍♂️ It's like a security guard locked outside his own building, yelling about safety! 🚫🔒
    blog.brycekerley.net/2026/03/0 #SecurityExpired #CertFail #SafeGuard #HackerNews #ngated

  10. March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029.

    Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you.

    certkit.io/blog/last-call-on-3 #PKI #WebPKI

  11. March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029.

    Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you.

    certkit.io/blog/last-call-on-3 #PKI #WebPKI

  12. CertKit Agent 1.6: RRAS support, deploy windows, and agent locking.

    Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized.

    certkit.io/blog/agent-1.6

    #CertificateAutomation #WebPKI

  13. CertKit Agent 1.6: RRAS support, deploy windows, and agent locking.

    Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized.

    certkit.io/blog/agent-1.6

    #CertificateAutomation #WebPKI

  14. Gibt’s eigentlich schon sinnvolle kommerzielle oder freie issuer für clientAuth Zertifikate? #webpki #cabforum #tls

  15. Gibt’s eigentlich schon sinnvolle kommerzielle oder freie issuer für clientAuth Zertifikate? #webpki #cabforum #tls

  16. Gibt’s eigentlich schon sinnvolle kommerzielle oder freie issuer für clientAuth Zertifikate? #webpki #cabforum #tls

  17. Gibt’s eigentlich schon sinnvolle kommerzielle oder freie issuer für clientAuth Zertifikate? #webpki #cabforum #tls

  18. #Heise:
    "
    "Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderem

    Eine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
    "
    heise.de/news/Passwort-Folge-4

    mp3: audio.podigee-cdn.net/2098722-

    10.9.2025

    Aaaa.. MS..

    #CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat

  19. #Heise:
    "
    "Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderem

    Eine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
    "
    heise.de/news/Passwort-Folge-4

    mp3: audio.podigee-cdn.net/2098722-

    10.9.2025

    Aaaa.. MS..

    #CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat

  20. #Heise:
    "
    "Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderem

    Eine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
    "
    heise.de/news/Passwort-Folge-4

    mp3: audio.podigee-cdn.net/2098722-

    10.9.2025

    Aaaa.. MS..

    #CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat

  21. #Heise:
    "
    "Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderem

    Eine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
    "
    heise.de/news/Passwort-Folge-4

    mp3: audio.podigee-cdn.net/2098722-

    10.9.2025

    Aaaa.. MS..

    #CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat

  22. #Heise:
    "
    "Passwort" Folge 40: Probleme mit Widerrufen, Verbindungsabbrüchen und anderem

    Eine pickepackevolle Folge, gefüllt unter anderem mit kundigem Exploitbau unter Linux, einem HTTP2-DoS und millionenfachen Zertifikatsrückrufen von Microsoft.
    "
    heise.de/news/Passwort-Folge-4

    mp3: audio.podigee-cdn.net/2098722-

    10.9.2025

    Aaaa.. MS..

    #CA #CertificateTransparency #Chrome #LetsEncrypt #Microsoft #MS #PKI #TLSZertifikat #WebPKI #Zertifikat

  23. CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): hacks.mozilla.org/2025/08/crli

    #RustLang #WebPKI #revocation #CRLite #clubcard #Firefox

  24. CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): hacks.mozilla.org/2025/08/crli

    #RustLang #WebPKI #revocation #CRLite #clubcard #Firefox

  25. CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): hacks.mozilla.org/2025/08/crli

    #RustLang #WebPKI #revocation #CRLite #clubcard #Firefox

  26. CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): hacks.mozilla.org/2025/08/crli

    #RustLang #WebPKI #revocation #CRLite #clubcard #Firefox

  27. CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): hacks.mozilla.org/2025/08/crli

    #RustLang #WebPKI #revocation #CRLite #clubcard #Firefox

  28. Within the #WebPKI, the "common name" is widely irrelevant afaik:

    infosec.exchange/@pft/11474541

    So the question is: what are the circumstances that can pose a security risk if IP addresses are included in the CN field.

  29. Firefox 136 looks poised to enforce Certificate Transparency.

    It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.

    While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.

    Originally posted on seirdy.one: See Original (POSSE). #Firefox #WebPKI

  30. Firefox 136 looks poised to enforce Certificate Transparency.

    It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.

    While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.

    Originally posted on seirdy.one: See Original (POSSE). #Firefox #WebPKI

  31. Firefox 136 looks poised to enforce Certificate Transparency.

    It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.

    While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.

    Originally posted on seirdy.one: See Original (POSSE). #Firefox #WebPKI

  32. Firefox 136 looks poised to enforce Certificate Transparency.

    It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.

    While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.

    Originally posted on seirdy.one: See Original (POSSE). #Firefox #WebPKI

  33. Firefox 136 looks poised to enforce Certificate Transparency.

    It may be late, but combined with CRLite (and its other Web PKI progress), it may soon be the browser with the most robust Web PKI support.

    While I would still say that Chromium generally wins on the security front, I’m happy to see the gap narrow with time and to see Firefox occasionally inch ahead in some areas.

    Originally posted on seirdy.one: See Original (POSSE). #Firefox #WebPKI

  34. New blog post: Post-OCSP certificate revocation in the Web PKI.

    With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.

    I think this is the most comprehensive current look at certificate revocation right now.

    #security #WebPKI #LetsEncrypt #TLS #OCSP

  35. New blog post: Post-OCSP certificate revocation in the Web PKI.

    With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.

    I think this is the most comprehensive current look at certificate revocation right now.

    #security #WebPKI #LetsEncrypt #TLS #OCSP

  36. New blog post: Post-OCSP certificate revocation in the Web PKI.

    With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.

    I think this is the most comprehensive current look at certificate revocation right now.

    #security #WebPKI #LetsEncrypt #TLS #OCSP

  37. New blog post: Post-OCSP certificate revocation in the Web PKI.

    With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.

    I think this is the most comprehensive current look at certificate revocation right now.

    #security #WebPKI #LetsEncrypt #TLS #OCSP

  38. New blog post: Post-OCSP certificate revocation in the Web PKI.

    With OCSP in all forms going away, I decided to look at the history and possible futures of certificate revocation in the Web PKI. I also threw in some of my own proposals to work alongside existing ones.

    I think this is the most comprehensive current look at certificate revocation right now.

    #security #WebPKI #LetsEncrypt #TLS #OCSP

  39. For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:

    • OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
    • CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
    • Short-lived certs (inc. ACME-STAR, Delegated Credentials, and notAfter)

    Anything else I should cover?

    #WebPKI #TLS

  40. For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:

    • OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
    • CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
    • Short-lived certs (inc. ACME-STAR, Delegated Credentials, and notAfter)

    Anything else I should cover?

    #WebPKI #TLS

  41. For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:

    • OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
    • CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
    • Short-lived certs (inc. ACME-STAR, Delegated Credentials, and notAfter)

    Anything else I should cover?

    #WebPKI #TLS

  42. For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:

    • OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
    • CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
    • Short-lived certs (inc. ACME-STAR, Delegated Credentials, and notAfter)

    Anything else I should cover?

    #WebPKI #TLS

  43. For a blog post I’m writing about dealing with certificate revocation, here are the topics I’m covering:

    • OCSP (inc. stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let’s Encrypt)
    • CRLs, inc. CRLite, CRLSets, and Let’s Revoke.
    • Short-lived certs (inc. ACME-STAR, Delegated Credentials, and notAfter)

    Anything else I should cover?

    #WebPKI #TLS

  44. OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.

  45. OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.

  46. OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.

  47. OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.

  48. OCSP Stapling: still a thing? I lose track of which of the various attempts at solving #WebPKI revocation are still current.

  49. Apropos of nothing, here's a fun question at the intersection of #linguistics and the #webpki. Given the following sentence:

    "...has determined that using the FQDN in the Certificate is no longer legally permitted."

    which of the following two things do you think is no longer legally permitted?