Learn more at https://www.certkit.io/
www.certkit.io/blog/should-...
#PKI #WebSecurity
www.certkit.io/blog/should-...
#PKI #WebSecurity
www.certkit.io/blog/dns-per...
#ACME #PKI
www.certkit.io/blog/dns-per...
#ACME #PKI
Wildcard vs SAN assumes certificates are painful to manage. But once you've automated for 47-day lifetimes, issuing 50 certs takes the same effort as one. The question shifts to security, not convenience.
www.certkit.io/blog/do-you-...
#PKI #WebSecurity
Wildcard vs SAN assumes certificates are painful to manage. But once you've automated for 47-day lifetimes, issuing 50 certs takes the same effort as one. The question shifts to security, not convenience.
www.certkit.io/blog/do-you-...
#PKI #WebSecurity
www.certkit.io/blog/certkit...
#SSL #PKI
www.certkit.io/blog/certkit...
#SSL #PKI
www.certkit.io/blog/how-acm...
#ACME #PKI
www.certkit.io/blog/how-acm...
#ACME #PKI
With RSA key exchange, that worked.
PFS broke their playbook. If you're still on TLS 1.2 without ECDHE, your traffic from 2019 might get decrypted tomorrow.
www.certkit.io/blog/perfect...
#TLS #PKI
With RSA key exchange, that worked.
PFS broke their playbook. If you're still on TLS 1.2 without ECDHE, your traffic from 2019 might get decrypted tomorrow.
www.certkit.io/blog/perfect...
#TLS #PKI
www.certkit.io/blog/searchi...
#Clickhouse #PKI
www.certkit.io/blog/searchi...
#Clickhouse #PKI
www.youtube.com/watch?v=HBaZ...
#javascript #errormonitoring
www.youtube.com/watch?v=HBaZ...
#javascript #errormonitoring
www.certkit.io/blog/searchi...
#PKI #CertificateTransparency
www.certkit.io/blog/searchi...
#PKI #CertificateTransparency
Part 1 of our series: www.certkit.io/blog/searchi...
#CertificateTransparency #PKI
Part 1 of our series: www.certkit.io/blog/searchi...
#CertificateTransparency #PKI
Most revoked certs keep working. Chrome, Firefox, Safari each block different revoked certs. The industry knows it's broken, so they're forcing 47-day expiration instead.
www.certkit.io/blog/certifi...
#PKI #CertificateManagement
Most revoked certs keep working. Chrome, Firefox, Safari each block different revoked certs. The industry knows it's broken, so they're forcing 47-day expiration instead.
www.certkit.io/blog/certifi...
#PKI #CertificateManagement
For an entire year, someone else had a perfectly legitimate certificate for their payment processing.
This is why we're getting 47-day certificates.
www.certkit.io/blog/bygones...
For an entire year, someone else had a perfectly legitimate certificate for their payment processing.
This is why we're getting 47-day certificates.
www.certkit.io/blog/bygones...
#cybersecurity #certificatemanagement #devops https://opsmtrs.com/46V2Oar
#cybersecurity #certificatemanagement #devops https://opsmtrs.com/46V2Oar
www.certkit.io/blog/47-day-...
www.certkit.io/blog/47-day-...
www.certkit.io/blog/why-you...
#devsecops #ssl #certificates
www.certkit.io/blog/why-you...
#devsecops #ssl #certificates
Do you have strong feels about certificates? I'd love to chat with you about it.
Do you have strong feels about certificates? I'd love to chat with you about it.
Remember when they lasted 3 years? Then 2? Then 1? Now we're speed-running toward daily renewals.
Your bash script from 2019 isn't ready for this
certkit.io/blog/why-we-built-certkit
Remember when they lasted 3 years? Then 2? Then 1? Now we're speed-running toward daily renewals.
Your bash script from 2019 isn't ready for this
certkit.io/blog/why-we-built-certkit