lucasmz · @lucasmz
9 followers · 179 posts · Server hachyderm.io

I want some views on this;

I pretty strongly believe that stapling and OCSP Must Staple should be the defaults, maybe even required on the web, maybe in all communication, at least when we're talking about globally trusted CAs. The only downside I see to it is offline access to private services in your network, but that's happening only every once in a while and it's possible that the OCSP cache might be valid for longer than that actually happens, right now Firefox being...

#ocsp #tls

Last updated 1 year ago

Hans Brender, Mr.OneDrive · @HansBrender
345 followers · 310 posts · Server mastodon.social

Secure your application traffic with Application Gateway mTLS

Rajesh Nautiyal, Senior Technical Program Manager ishappy to share that Azure Application Gateway now supports mutual transport layer security (mTLS) and online certificate status protocol (OCSP). Here, he is covering what mTLS is, how it works, when to consider it, and how to verify it in Application Gateway.

read more here: azure.microsoft.com/de-de/blog

#microsoft #azure #mtls #ocsp

Last updated 2 years ago

Jeroen Habets · @jeroen
22 followers · 326 posts · Server mastodon.habets.dev

utrecht.nl internet.nl result: 2 red alerts :( :(, 2 warnings :(, 1 green :)
internet.nl/site/utrecht.nl/18

Fond of services @GemeenteUtrecht@twitter.com (!!!) Pls tackle this lack of in Q1 2013.
, , Stapling, ,

#gemeenteutrecht #kudos #security #IPv6 #hsts #ocsp #csp #rpki

Last updated 2 years ago

Andy · @andy
3 followers · 32 posts · Server tux.social

Das war ein komischer Fehler. Am Wochenende und Montag lief ein normaler ICMP traceroute auf ocsp.digicert.com durch und ein TCP traceroute auf Port 80 meldete als letztes den Edge-Router vom Provider.
Mittlerweile antwortet ocsp.digicert.com wieder auf Port 80. Es funktioniert somit wieder. Entweder bin ich auf eine Denylist gekommen, oder da wurde etwas verkonfiguriert.

#ocsp #digicert #internetbroken

Last updated 2 years ago

Andy · @andy
3 followers · 26 posts · Server tux.social

Bin ich der einzige der gerade mit Zertifikatsprüfung Probleme hat?

$ curl --cert-status -v 'metacheles.de/'
[…]
* issuer: C=US; O=Cloudflare, Inc.; CN=Cloudflare Inc ECC CA-3
* SSL certificate verify ok.
* No OCSP response received

$ curl --cert-status -v 'substack.com/'
[…]
* issuer: C=US; O=Cloudflare, Inc.; CN=Cloudflare Inc ECC CA-3
* SSL certificate verify ok.
* No OCSP response received

#cloudflare #ocsp

Last updated 2 years ago

jomo · @jomo
1202 followers · 4801 posts · Server mstdn.io

Looks like some of 's servers are sending HTML instead of OCSP responses.

Status page claims everything is ok 🤡

#digicert #ocsp

Last updated 2 years ago

Harld :masto: · @harld
1027 followers · 2654 posts · Server masto.ai

Zo, op een regenachtige zondagmiddag repareer je gewoon je server van je eigen ....

#ocsp #pki #nerd

Last updated 2 years ago

Walter · @walter
81 followers · 501 posts · Server programist.ro

Also, if you can't find any websites, just use the to get a list of their Staging or UAT subdomains.

And now you've "beaten" while talking in plain text right under their noses and using their expensive infrastructure money, you don't even need ! 🤣

[3/3]

#rfc6960 #ocsp #chatcontrol #ROT13 #fnord

Last updated 2 years ago

Cy · @cy
179 followers · 9278 posts · Server mstdn.io

Wow, sucks more than I realized. It protects neither the server, nor the client, but only provides protection and power to the certificate authority. Basically it makes it easier for them to revoke a certificate. So it's just yet another way for SSL certificate authorities to twist the thumb screws. No wonder it's so much of a pain to set up!

#ocsp

Last updated 2 years ago

Steve Foerster 🇩🇲 · @stevefoerster
447 followers · 1692 posts · Server mastodon.oeru.org

After I upgraded my MacOS version, LibreOffice wouldn't start. Now I know why. And now I think it's time I switched my MacBook Air to .

fsf.org/news/the-problems-with

#linux #ocsp

Last updated 4 years ago

😷 Jan Wildeboer · @jwildeboer
4159 followers · 13178 posts · Server social.wildeboer.net

updates their documentation, clarifies it is not spying on what apps you run with their , understands the arguments and promises changes like scrubbing all IP addresses from the logs, switching to encrypted communication. Good. support.apple.com/en-us/HT2024

#apple #ocsp

Last updated 4 years ago

可口可偷着乐 🌈 :trans_flag: · @bgme
1016 followers · 16129 posts · Server bgme.me

安全警告:
由于 OCSP 是明文HTTP以及macOS 强制验证 OCSP 的设计,所以ISP只需要进行简单的监听即可知晓你系统中运行着什么软件。
如果你在 macOS 系统中安装了 ShadowsocksX-NG 这种不太符合社会主义核心价值观的软件,macOS 这种设计毫无疑问给你带来了潜在的隐私泄漏风险以及人身安全风险。
twitter.com/quakewang/status/1

#隐私与安全 #ocsp #macos

Last updated 4 years ago

Tuxicoman · @tuxicoman
1324 followers · 14622 posts · Server social.jesuislibre.net

Quel est l'intérêt de tester la signature au lancement sur les applications déjà installées?

Scénario1 : Un éditeur déclare s'être fait voler ses clés de chiffrement. On supprime ses logiciels de tous les Mac du monde ??

#ocsp

Last updated 4 years ago

Tuxicoman · @tuxicoman
1337 followers · 14809 posts · Server social.jesuislibre.net

Quel est l'intérêt de tester la signature au lancement sur les applications déjà installées?

Scénario1 : Un éditeur déclare s'être fait voler ses clés de chiffrement. On supprime ses logiciels de tous les Mac du monde ??

#ocsp

Last updated 4 years ago

Gonçalo Valério · @dethos
295 followers · 1159 posts · Server s.ovalerio.net

"Even if the certificate has an OCSP staple ... Chrome always sends a blocking request to the Certificate Authority's server when connecting to a website that uses an EV certificate and this request can take hundreds of milliseconds. To make things worse, if the CA's server is down, your users see an error page instead of your website."

aaronpeters.nl/blog/ev-certifi

#tls #pki #ocsp #security #performance

Last updated 5 years ago

Romain Tartière 😈 · @smortex
215 followers · 1114 posts · Server mamot.fr

1/3 ­— Playing with and with certificates. The documentation lacks details about intermediate certificates, so here are the results of my tests. Everything is logical but since there are a lot of moving parts, forgetting a step is easy.

#dnsdist #ocsp #stapling #letsencrypt

Last updated 5 years ago

Romain Tartière 😈 · @smortex
215 followers · 1114 posts · Server mamot.fr

When says it cannot connect to the submission server because of an « unknown error », what it really means is sometimes:

« The server certificate has the Must-Staple extension, but the server did not provide OCSP stapling information ».

Weird thing, it could drop the connection earlier, but does it only after server and client key exchange. Hard to debug 😨

Pro tips, OCSP stapling is not supported by your MTA.

#thunderbird #tls #ocsp

Last updated 5 years ago