home.social

#x509 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #x509, aggregated by home.social.

  1. Oh, nice! I pulled all the latest changes for Hare's stdlib and I saw `crypto::x509` come down!

    #HareLang #TLS #x509

  2. От Root CA до User Authorization в nginx+apache. Часть 2. Отзыв сертификатов, CRL и OCSP

    Сертификат скомпрометирован, а срок действия ещё не вышел — как сказать клиентам «больше ему не верьте»? Разбираем оба механизма отзыва, CRL и OCSP: отзыв, генерация и публикация списков, responder, stapling в nginx/apache. С полным справочником всех параметров.

    habr.com/ru/articles/1051674/

    #OpenSSL #PKI #OCSP #CRL #отзыв_сертификатов #X509 #certificate_authority #OCSP_stapling #nginx #информационная_безопасность

  3. От Root CA до User Authorization в nginx+apache. Часть 2. Отзыв сертификатов, CRL и OCSP

    Сертификат скомпрометирован, а срок действия ещё не вышел — как сказать клиентам «больше ему не верьте»? Разбираем оба механизма отзыва, CRL и OCSP: отзыв, генерация и публикация списков, responder, stapling в nginx/apache. С полным справочником всех параметров.

    habr.com/ru/articles/1051674/

    #OpenSSL #PKI #OCSP #CRL #отзыв_сертификатов #X509 #certificate_authority #OCSP_stapling #nginx #информационная_безопасность

  4. От Root CA до User Authorization в nginx+apache. Часть 2. Отзыв сертификатов, CRL и OCSP

    Сертификат скомпрометирован, а срок действия ещё не вышел — как сказать клиентам «больше ему не верьте»? Разбираем оба механизма отзыва, CRL и OCSP: отзыв, генерация и публикация списков, responder, stapling в nginx/apache. С полным справочником всех параметров.

    habr.com/ru/articles/1051674/

    #OpenSSL #PKI #OCSP #CRL #отзыв_сертификатов #X509 #certificate_authority #OCSP_stapling #nginx #информационная_безопасность

  5. #DigiCert customer support compromised with .scr ZIP attachment 🤷

    During our investigation between 2026-04-14 and 2026-04-17, as DigiCert identified certificates potentially affected by the threat actor’s actions, we revoked them. DigiCert revoked 60 certificates issued from the following CAs:

    • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
    • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
    • Verokey High Assurance Secure Code EV

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    #x509 #infosec

  6. CW: work, crypto

    Okay, I finally figured out how this proof algorithm works on a mathematical layer.

    Now the pending question is whether we can describe a ECDSA signature as a mathematical function fulfilling the requirements of this algorithm in order to proof we *have* a signature of arbitrary data using a particular private key without *revealing* the signature itself.

    Damn. This is brainfuck. But this is *amazing* brainfuck. And damn, this algorithm is crazy.

    #matrix #X509 #crypto #ZKP

  7. CW: work, crypto

    Okay, I finally figured out how this proof algorithm works on a mathematical layer.

    Now the pending question is whether we can describe a ECDSA signature as a mathematical function fulfilling the requirements of this algorithm in order to proof we *have* a signature of arbitrary data using a particular private key without *revealing* the signature itself.

    Damn. This is brainfuck. But this is *amazing* brainfuck. And damn, this algorithm is crazy.

    #matrix #X509 #crypto #ZKP

  8. RIP #Volksverschlüsselung, du wirst nicht vermisst werden! heise.de/news/Bald-ist-Schluss

    Warum wählen eigentlich Projekte, die verschlüsselte Kommunikation massentauglich machen wollen, regelmäßig so beknackte Nerd-Namen und -Akronyme? 🙄 Siehe auch p≡p.

    #Security #Encryption #SMIME #X509 #Fraunhofer

  9. RIP #Volksverschlüsselung, du wirst nicht vermisst werden! heise.de/news/Bald-ist-Schluss

    Warum wählen eigentlich Projekte, die verschlüsselte Kommunikation massentauglich machen wollen, regelmäßig so beknackte Nerd-Namen und -Akronyme? 🙄 Siehe auch p≡p.

    #Security #Encryption #SMIME #X509 #Fraunhofer

  10. We have just released the first version of voa-core, a #RustLang library for access to verifiers in #VOA structures. 🎁 🦀

    crates.io/crates/voa-core/0.1.0

    VOA, short for "File Hierarchy for the Verification of OS Artifacts", is a way of providing and using verifiers for digital signatures in a stateless manner, for various cryptographic technologies:
    uapi-group.org/specifications/

    Thanks to @hko for his work on this and an upcoming #OpenPGP backend! 🥳

    #UAPIGroup #ArchLinux #DigitalSignature #SSH #X509 #STF

  11. We have just released the first version of voa-core, a #RustLang library for access to verifiers in #VOA structures. 🎁 🦀

    crates.io/crates/voa-core/0.1.0

    VOA, short for "File Hierarchy for the Verification of OS Artifacts", is a way of providing and using verifiers for digital signatures in a stateless manner, for various cryptographic technologies:
    uapi-group.org/specifications/

    Thanks to @hko for his work on this and an upcoming #OpenPGP backend! 🥳

    #UAPIGroup #ArchLinux #DigitalSignature #SSH #X509 #STF

  12. Happily sending around signed and encrypted emails that use S/MIME certificates that I created myself on my own CA. And as my mail server (that I also run myself) has DKIM, DMARC, SPF set up correctly, that also works. Nice!

    #SelfHost #CA #SMIME #x509 #eMail

  13. Happily sending around signed and encrypted emails that use S/MIME certificates that I created myself on my own CA. And as my mail server (that I also run myself) has DKIM, DMARC, SPF set up correctly, that also works. Nice!

    #SelfHost #CA #SMIME #x509 #eMail

  14. So now that I have my own s/mime certificate generated and installed, here's the SHA256 fingerprint:

    19dae1a388af5c91e3dc53d89e3efdaef3f24878b9d37f809463ee801f3eae25

    Should you get an email from me, it will be signed and with this fingerprint you can verify that indeed it was me who sent it.

    I know almost no one will ever actually do this verification, but it is reassuring to me that you can :)

    #SelfHost #email #SMIME #CA #x509

  15. So now that I have my own s/mime certificate generated and installed, here's the SHA256 fingerprint:

    19dae1a388af5c91e3dc53d89e3efdaef3f24878b9d37f809463ee801f3eae25

    Should you get an email from me, it will be signed and with this fingerprint you can verify that indeed it was me who sent it.

    I know almost no one will ever actually do this verification, but it is reassuring to me that you can :)

    #SelfHost #email #SMIME #CA #x509

  16. I have brain dumped the process at codeberg.org/jwildeboer/gists/ and will work on an extended version as blog post in the next few days. Big shoutout to @ben again for getting the process up and running in the first place!

    If you want to get a signed email from me to see what happens in your mail client, DM me an email address and I will send a s/mime signed email to you :)

    6/6

    #SelfHost #eMail #SMIME #CA #x509

  17. I have brain dumped the process at codeberg.org/jwildeboer/gists/ and will work on an extended version as blog post in the next few days. Big shoutout to @ben again for getting the process up and running in the first place!

    If you want to get a signed email from me to see what happens in your mail client, DM me an email address and I will send a s/mime signed email to you :)

    6/6

    #SelfHost #eMail #SMIME #CA #x509

  18. If I understand the whole s/mime stuff correctly, I can send you a signed email and your mail client should be able to extract my public key from that. You reply with a signed mail, I can extract your public key. Now we can send encrypted emails :) Your mail client/operating system won't trust my certificate as it is signed by my CA (Certificate Authority), but it should still work.

    5/6

    #SelfHost #eMail #SMIME #CA #x509

  19. If I understand the whole s/mime stuff correctly, I can send you a signed email and your mail client should be able to extract my public key from that. You reply with a signed mail, I can extract your public key. Now we can send encrypted emails :) Your mail client/operating system won't trust my certificate as it is signed by my CA (Certificate Authority), but it should still work.

    5/6

    #SelfHost #eMail #SMIME #CA #x509

  20. After some help from @ben and some swearing about PKCS12 (add a password when you package the .p12 file so that Android and iOS will be able to import it) and Keychain on MacOS, it’s working. S/mime signed and encrypted mails with certificates from my own CA.

    4/6

    #SelfHost #eMail #SMIME #CA #x509

  21. If you want to play with free S/MIME certs for e-mail signing and encryption, acme.castle.cloud does that letsencrypt style with ACME and certbot :) Made and operated by the Centre Tecnològic de Telecomunicacions de Catalunya (CTTC). A non-profit research institution based in Castelldefels (Barcelona).

    3/6

    #SelfHost #eMail #SMIME #CA #x509

  22. KEKS кодек и криптографические сообщения

    Данная статья напоминает о проблемах X.509 PKI и реализаций ASN.1. Предлагает компактный, быстрый, детерминированный, потоковый и простой формат кодирования данных KEKS, а также криптографические сообщения для подписи и шифрования данных с поддержкой пост-квантовых алгоритмов.

    habr.com/ru/articles/923810/

    #c #go #python #keks #asn1 #x509 #openssl #криптография #pqc #hpke #pgp #cms

  23. KEKS кодек и криптографические сообщения

    Данная статья напоминает о проблемах X.509 PKI и реализаций ASN.1. Предлагает компактный, быстрый, детерминированный, потоковый и простой формат кодирования данных KEKS, а также криптографические сообщения для подписи и шифрования данных с поддержкой пост-квантовых алгоритмов.

    habr.com/ru/articles/923810/

    #c #go #python #keks #asn1 #x509 #openssl #криптография #pqc #hpke #pgp #cms

  24. KEKS кодек и криптографические сообщения

    Данная статья напоминает о проблемах X.509 PKI и реализаций ASN.1. Предлагает компактный, быстрый, детерминированный, потоковый и простой формат кодирования данных KEKS, а также криптографические сообщения для подписи и шифрования данных с поддержкой пост-квантовых алгоритмов.

    habr.com/ru/articles/923810/

    #c #go #python #keks #asn1 #x509 #openssl #криптография #pqc #hpke #pgp #cms

  25. 又忍不住吐槽一番,X.509 證書只能有一個簽發方,PIV 使用 X.509 證書,一個 PIV 設備只有一個認證證書槽,而 PIV 生態裡常見的用途(比如 FreeIPA 客戶端證書登錄)都要求使用服務方簽發的證書,這實質上導致了一個 PIV 設備僅能用於一個服務的一個身份,與現如今用戶的一般需求不相稱(用戶一般是使用一個設備對應很多個服務上的一個身份)。
    可能還是設計於較近時代的 FIDO2 更適合於這種場景,但是又會遇到一些其他的問題,比如平臺不支持 FIDO(點名批評 FreeIPA),比如 HTTPS 客戶端認證不支持 FIDO(FIDO 現階段在瀏覽器裡還是只能由網站通過 JS 調用)……
    mastodon.yuuta.moe/@coelacanth

    #PIV #X509 #FIDO

  26. Happy that I’ve successfully set up my own local #homelab #x509 and #SSH #CertificateAuthority with #StepCA. I imported a root #CA chain that I generated on my own separately.

    From this, I learned that StepCA did not like the human-readable headings — above the “BEGIN CERTIFICATE” statements — in .crt/.pem files that #OpenSSL generated. I don’t know they are called or any CLI option that added them to the #PEM files. However, when I removed the headers, the StepCA server started without error.

  27. In anybody knowing ASN.1 around? I'm seeking a way to constrain a Sequence having three optional elements that alt least one of it must be present.

    I'd also appreciate pointer where to ask. many thanks in advance.

    #asn #asn1 #x509 #pleaseretoot

  28. Other People Have Lives – I Have Domains

    These are just some boring update notifications from the elkemental Webiverse. The elkement blog has recently celebrated its fifth anniversary, and the punktwissen blog will turn five in December. Time to celebrate this - with new domain names that says exactly what these sites are - the 'elkement . blog' and the 'punktwissen . blog' (Edit: which now - in 2020 - point to a copy of these sites elsewhere ;-) Edit again in 2023: And now the main name of this site is elkement.art […]

    elkement.art/2017/06/06/other-