Oh, look! The US #military is treating #cybersecurity like it's an optional accessory! 🎖️🔐 Why bother with updated #TLS #certificates when you can just let everyone enjoy a nostalgic trip back to the early 2000s? 🚀💾 "Welcome to #LWC #Communities," where #expired security is the new norm. 🤦‍♂️
https://www.cyber.mil/stigs/downloads #outdated #HackerNews #ngated
Welcome to LWC Communities!

Shinsegae Confirms An Employee Stole Gift Certificates Bought By NCT's Jaemin For His Fans - KpopNewsHub – Latest K-Pop News, Idols & Korean Entertainment

Upon investigation, Shinsegae Group has confirmed the allegations that an employee stole multiple gift certificates that NCT’s Jaemin had purchased as gifts

Kpop News Hub
ZeroSSL - Please add IPv6 support and a DNS-PERSIST-01 validation method. #ZeroSSL #IPv6 #SSL #TLS #certificates #networking
ZeroSSL - Please add IPv6 support and a DNS-PERSIST-01 validation method. #ZeroSSL #IPv6 #SSL #TLS #certificates #networking
WebPKI and You

There’s been a push over the last twelve years to move web traffic off unencrypted HTTP to encrypted HTTPS, to protect the general public from dragnet surveillance, gaping assholes on public wifi>airpwn, backhauls over unencrypted satellites, that kinda thing. HTTPS relies on a public key infrastructure to make sure only authorized servers have keys for specific websites. [>oid]: an OID or “Object IDentifier” is intended [brs]: https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.1.8.pdf [crtsh]: https://crt.sh/?q=blog.brycekerley.net [lol-diginotar]: https://en.wikipedia.org/wiki/DigiNotar#Issuance_of_fraudulent_certificates [iv-ocsp]: https://www.imperialviolet.org/2011/03/18/revocation.html [>mac-ocsp]: Jeff Johnson’s [>crlite]: these use cascading bloom filters which [>short-lived]: the CA/BF baseline requirements [trustico-chrome]: https://security.googleblog.com/2017/09/chromes-plan-to-distrust-symantec.html [trustico-gone]: https://arstechnica.com/information-technology/2018/03/trustico-website-goes-dark-after-someone-drops-critical-flaw-on-twitter/ [trustico-compromise]: https://groups.google.com/g/mozilla.dev.security.policy/c/wxX4Yv0E3Mk/m/o1cdfx2nAQAJ [>enclaves]: Amazon Web Services (AWS) and [>history]: i mean, i remember from when it happened [>parasite]: You may have realized that I don’t think [van-halen]: https://snackstack.net/2023/07/03/in-search-of-van-halens-brown-mms/ [>osi]: I’m not going to hit you with a [>responsibility]: in every part of your life! [>bloom]: [>later]: At time of publishing, it’s March 8, 2026 [hsts]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security [>hsts]: This is generally a hardcoded value, [>cattle]: “cattle” is when there’s [ari]: https://letsencrypt.org/2025/09/16/ari-rfc [>caddy-ari]: I checked Caddy, the front-end server [>left]: there may be value in trying to renew [audits]: https://cabforum.org/about/information/auditors-and-assessors/audit-criteria/

Bryce’s Blog

🔄 NEW: Kubernetes Certificate Rotation Guide!

Rotate expired certs without downtime. kubeadm, manual & automated approaches for production clusters.

📖 Read: https://devopstales.github.io/kubernetes/k8s-cert/?utm_source=twitter&utm_medium=social

#Kubernetes #Certificates #DevOps #SRE

Kubernetes Certificate Rotation

Complete guide to Kubernetes certificate rotation - automatic and manual methods for kubeadm, RKE2, and K3s clusters.

DevOpsTales

Using #Linux with #SecureBoot via #UEFI on slightly older #hardware ?

If you don't know of, or if you're unsure if you'll be affected by the loss of secure #certificates in July 2026, here are some resources to help.

Check if your OEM has, or will, provide their part of the required firmware updates here...

LVFS - Linux Vendor Firmware Service: https://fwupd.org/

Problem overview and current details on fixes and expectations here...

Fwupd & FwupdPlugin Notes - https://fwupd.github.io/libfwupdplugin/uefi-db.html

LVFS: Home

With DNS-PERSIST-01, Let’s Encrypt users can validate their domains without having to update DNS records every time they issue or renew a certificate.
https://linuxiac.com/lets-encrypt-introduces-dns-persist-01-for-persistent-acme-dns-validation/

#letsencrypt #certificates #security

ZeroSSL a kind request, supporting DNS-PERSIST-01 validation method would be just awesome! - Thanks

#ZeroSSL #EuropeanAlternatives #TLS #Validation #Certificates #LetsEncrypt