Stéphane Bortzmeyer · @bortzmeyer
7540 followers · 76188 posts · Server mastodon.gougere.fr
Stéphane Bortzmeyer · @bortzmeyer
6698 followers · 75532 posts · Server mastodon.gougere.fr

Tiens, envoyer un certificat au serveur depuis un programme est bien plus simple que je ne pensais. (C'est peut-être pour ça qu'il n'y a aucune documentation.)

#pkix #python #tls

Last updated 3 years ago

Stéphane Bortzmeyer · @bortzmeyer
6407 followers · 75263 posts · Server mastodon.gougere.fr

Et ce matin, une Autorité de Certification basque a cassé le site Web de La Poste.

#mondialisation #x509 #pkix #viedelinternet

Last updated 4 years ago

Stéphane Bortzmeyer · @bortzmeyer
6407 followers · 75263 posts · Server mastodon.gougere.fr

J'aime tant les certificats numériques que je trouve cette idée, créer automatiquement plein de certificats ayant une très courte durée de vie, sympa.

8739: Support for Short-Term, Automatically-Renewed () Certificates in Automated Certificate Management Environment ()

bortzmeyer.org/8739.html

#rfc #star #acme #pkix #x509

Last updated 5 years ago

· @Creideiki
99 followers · 1832 posts · Server mastodon.social

What I ended up doing was publish -TA assertions for the root certificate in , and hope that it doesn't change too often. Because they don't bother publishing a policy. This means anyone who can fool can publish fake certificates for my domain, but at least random governments and enterprise boxes can't.

#pkix #letsencrypt #dnssec #tls #mitm

Last updated 6 years ago

· @Creideiki
99 followers · 1832 posts · Server mastodon.social

DANE support is basically nonexistent. By default, generates a new key every time it renews a certificate, meaning -EE and -EE requires manual intervention every single time. Since a few months back, you can tell to keep the same key forever, but should you want to do key rollover less frequently you get to handle -EE and -EE manually anyway.

#certbot #dane #pkix

Last updated 6 years ago