home.social

#x509 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #x509, aggregated by home.social.

  1. Oh, nice! I pulled all the latest changes for Hare's stdlib and I saw `crypto::x509` come down!

    #HareLang #TLS #x509

  2. Oh, nice! I pulled all the latest changes for Hare's stdlib and I saw `crypto::x509` come down!

  3. Oh, nice! I pulled all the latest changes for Hare's stdlib and I saw `crypto::x509` come down!

    #HareLang #TLS #x509

  4. Oh, nice! I pulled all the latest changes for Hare's stdlib and I saw `crypto::x509` come down!

    #HareLang #TLS #x509

  5. Oh, nice! I pulled all the latest changes for Hare's stdlib and I saw `crypto::x509` come down!

    #HareLang #TLS #x509

  6. От Root CA до User Authorization в nginx+apache. Часть 2. Отзыв сертификатов, CRL и OCSP

    Сертификат скомпрометирован, а срок действия ещё не вышел — как сказать клиентам «больше ему не верьте»? Разбираем оба механизма отзыва, CRL и OCSP: отзыв, генерация и публикация списков, responder, stapling в nginx/apache. С полным справочником всех параметров.

    habr.com/ru/articles/1051674/

    #OpenSSL #PKI #OCSP #CRL #отзыв_сертификатов #X509 #certificate_authority #OCSP_stapling #nginx #информационная_безопасность

  7. От Root CA до User Authorization в nginx+apache. Часть 2. Отзыв сертификатов, CRL и OCSP

    Сертификат скомпрометирован, а срок действия ещё не вышел — как сказать клиентам «больше ему не верьте»? Разбираем оба механизма отзыва, CRL и OCSP: отзыв, генерация и публикация списков, responder, stapling в nginx/apache. С полным справочником всех параметров.

    habr.com/ru/articles/1051674/

    #OpenSSL #PKI #OCSP #CRL #отзыв_сертификатов #X509 #certificate_authority #OCSP_stapling #nginx #информационная_безопасность

  8. От Root CA до User Authorization в nginx+apache. Часть 2. Отзыв сертификатов, CRL и OCSP

    Сертификат скомпрометирован, а срок действия ещё не вышел — как сказать клиентам «больше ему не верьте»? Разбираем оба механизма отзыва, CRL и OCSP: отзыв, генерация и публикация списков, responder, stapling в nginx/apache. С полным справочником всех параметров.

    habr.com/ru/articles/1051674/

    #OpenSSL #PKI #OCSP #CRL #отзыв_сертификатов #X509 #certificate_authority #OCSP_stapling #nginx #информационная_безопасность

  9. Researching #x509 #EIDAS stuff regarding organizationIdentifier, clicking through some links, following a link to the Browser CA Bugzilla (bugzilla.mozilla.org/show_bug.)

    Be greeted by a bug from @q

    Small world

  10. Researching #x509 #EIDAS stuff regarding organizationIdentifier, clicking through some links, following a link to the Browser CA Bugzilla (bugzilla.mozilla.org/show_bug.)

    Be greeted by a bug from @q

    Small world

  11. Researching #x509 #EIDAS stuff regarding organizationIdentifier, clicking through some links, following a link to the Browser CA Bugzilla (bugzilla.mozilla.org/show_bug.)

    Be greeted by a bug from @q

    Small world

  12. Researching #x509 #EIDAS stuff regarding organizationIdentifier, clicking through some links, following a link to the Browser CA Bugzilla (bugzilla.mozilla.org/show_bug.)

    Be greeted by a bug from @q

    Small world

  13. #DigiCert customer support compromised with .scr ZIP attachment 🤷

    During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:

    • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
    • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
    • Verokey High Assurance Secure Code EV

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    #x509 #infosec

  14. #DigiCert customer support compromised with .scr ZIP attachment 🤷

    During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:

    • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
    • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
    • Verokey High Assurance Secure Code EV

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    #x509 #infosec

  15. #DigiCert customer support compromised with .scr ZIP attachment 🤷

    During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:

    • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
    • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
    • Verokey High Assurance Secure Code EV

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    #x509 #infosec

  16. #DigiCert customer support compromised with .scr ZIP attachment 🤷

    During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:

    • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
    • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
    • Verokey High Assurance Secure Code EV

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    #x509 #infosec

  17. #DigiCert customer support compromised with .scr ZIP attachment 🤷

    During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:

    • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
    • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
    • Verokey High Assurance Secure Code EV

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    #x509 #infosec

  18. RE: infosec.exchange/@paulehoffman

    Side note: this is why things like "multi-perapective corroboration" for domain validation do not work.

    When every single packet to .ir nameservers and servers inside Iran pass through two (yes, 2!) gateways, then those controlling the gateways can acquire a valid domain validation certificate for any .ir domain or any server located in Iran.

    #x509 #dns #dnssec #certificate

  19. RE: infosec.exchange/@paulehoffman

    Side note: this is why things like "multi-perapective corroboration" for domain validation do not work.

    When every single packet to .ir nameservers and servers inside Iran pass through two (yes, 2!) gateways, then those controlling the gateways can acquire a valid domain validation certificate for any .ir domain or any server located in Iran.

    #x509 #dns #dnssec #certificate

  20. RE: infosec.exchange/@paulehoffman

    Side note: this is why things like "multi-perapective corroboration" for domain validation do not work.

    When every single packet to .ir nameservers and servers inside Iran pass through two (yes, 2!) gateways, then those controlling the gateways can acquire a valid domain validation certificate for any .ir domain or any server located in Iran.

    #x509 #dns #dnssec #certificate

  21. RE: abyssdomain.expert/@filippo/11

    An archive of all CT-logged certificates with all the tools needed for an analysis! No more scraping.

    #ctlog #x509 #certificate

  22. RE: abyssdomain.expert/@filippo/11

    An archive of all CT-logged certificates with all the tools needed for an analysis! No more scraping.

    #ctlog #x509 #certificate

  23. RE: abyssdomain.expert/@filippo/11

    An archive of all CT-logged certificates with all the tools needed for an analysis! No more scraping.

    #ctlog #x509 #certificate

  24. So @letsencrypt have put out a new blog post about shorter lives for certs moving forward (45days by 2028), but I've still not seen any movement on deploying the "shortlived" profile (and as a result IP address certs) from their post back in July. It's all been up on the test Staging servers since then.

    Does anybody have any idea when this will finally go live?

    It's in the docs, but no mention that it is restricted to invited users only still

    letsencrypt.org/docs/profiles/

    #x509 #LetsEncrypt #ip

  25. So @letsencrypt have put out a new blog post about shorter lives for certs moving forward (45days by 2028), but I've still not seen any movement on deploying the "shortlived" profile (and as a result IP address certs) from their post back in July. It's all been up on the test Staging servers since then.

    Does anybody have any idea when this will finally go live?

    It's in the docs, but no mention that it is restricted to invited users only still

    letsencrypt.org/docs/profiles/

    #x509 #LetsEncrypt #ip

  26. So @letsencrypt have put out a new blog post about shorter lives for certs moving forward (45days by 2028), but I've still not seen any movement on deploying the "shortlived" profile (and as a result IP address certs) from their post back in July. It's all been up on the test Staging servers since then.

    Does anybody have any idea when this will finally go live?

    It's in the docs, but no mention that it is restricted to invited users only still

    letsencrypt.org/docs/profiles/

    #x509 #LetsEncrypt #ip

  27. So @letsencrypt have put out a new blog post about shorter lives for certs moving forward (45days by 2028), but I've still not seen any movement on deploying the "shortlived" profile (and as a result IP address certs) from their post back in July. It's all been up on the test Staging servers since then.

    Does anybody have any idea when this will finally go live?

    It's in the docs, but no mention that it is restricted to invited users only still

    letsencrypt.org/docs/profiles/

    #x509 #LetsEncrypt #ip

  28. So @letsencrypt have put out a new blog post about shorter lives for certs moving forward (45days by 2028), but I've still not seen any movement on deploying the "shortlived" profile (and as a result IP address certs) from their post back in July. It's all been up on the test Staging servers since then.

    Does anybody have any idea when this will finally go live?

    It's in the docs, but no mention that it is restricted to invited users only still

    letsencrypt.org/docs/profiles/

    #x509 #LetsEncrypt #ip

  29. % openssl x509 -in /Applications/zoom.us.app/Contents/Resources/BBMMRoot.crt -text

    Validity
    Not Before: Feb 8 00:00:00 2010 GMT
    Not After : Feb 7 23:59:59 2020 GMT
    Subject: C=US, O=Thawte, Inc., CN=Thawte SSL CA

    🧐

    #Zoom #x509

  30. % openssl x509 -in /Applications/zoom.us.app/Contents/Resources/BBMMRoot.crt -text

    Validity
    Not Before: Feb 8 00:00:00 2010 GMT
    Not After : Feb 7 23:59:59 2020 GMT
    Subject: C=US, O=Thawte, Inc., CN=Thawte SSL CA

    🧐

    #Zoom #x509