Reminder: Die gültigen #Zertifikat-Laufzeiten schrumpfen.

🟡 15. März 2026: 200 Tage ☹️
🟠 15. März 2027: 100 Tage 🤢
🔴 15. März 2029: 47 Tage 🤮

Unser Status:
#LetsEncrypt (wo einfach möglich) aktiviert
✅ 30-Tage-Zertifikate der internen AD CS PKI für Intranetdienste auf #WindowsServer und #Linux mit #PowerShell vollautomatisiert
⏳ AD FS, Exchange

https://www.heise.de/news/47-Tage-CAs-und-Browserhersteller-beschliessen-kuerzere-Laufzeit-fuer-Zertifikate-10352867.html

#sysadmin #admin #itsicherheit #zertifikate #tls #ssl #reminder #adcs #adfs #pki #intranet #internet

Beschlossen: Lebensdauer für TLS-Serverzertifikate sinkt auf 47 Tage

Von derzeit maximal dreizehn Monaten sinkt die Gültigkeit auf anderthalb. Allerdings mit jahrelanger Übergangsfrist für Admins.

heise online

[Перевод] Easy-RSA 3 и Public Key Infrastructure (PKI)

Представленный материал по большей части является переводом краткого руководства Easy-RSA 3 с некоторыми дополнениями. Сухое и формализованное изложение не предполагает украшательства картинками. P.S. Адептам рунглиша с острой аллергической реакцией и когнитивным диссонансом к русскоязычным терминам и сокращениям просьба не беспокоиться.

https://habr.com/ru/articles/1012396/

#ssl #tls #easyrsa #openvpn #pki #openssl

Easy-RSA 3 и Public Key Infrastructure (PKI)

1. Введение в Инфраструктуру открытого ключа 2. Easy-RSA 3 Введение в Инфраструктуру открытого ключа Используемая терминология ИОК / PKI (Public Key Infrastructure) — инфраструктура открытого...

Хабр

Mass revocation gives you 24 hours and thousands of certs to replace. ARI (RFC 9773) automates it, but only if your ACME client is always running.

Certbot uses a cron job. acme.sh has no ARI support.

https://www.certkit.io/blog/ari-solves-mass-certificate-revocation

#PKI #TLS

ACME Renewal Information (ARI) solves mass certificate revocation

When a CA has to revoke hundreds of thousands of certificates on a short deadline, email notifications aren't enough. ARI is the protocol that lets the CA tell your client directly: renew now. Here's how it works, and why most ACME clients can't actually respond in time.

CertKit SSL Certificate Management

LE is so advanced in every aspect, that competitors like Actalis are practically no viable alternatives. I tried Actalis free ACME certs for a while, then it started throwing errors about my quota (which should be unlimited btw). And we’re not even talking about stuff like DNS-PERSIST-01.

If people want European alternatives, then those alternatives should start delivering!

@icing

#acme #cert #letsencrypt #pki

RE: https://chaos.social/@icing/116214853150027314

CertKit now supports ACME ARI and 6-day certificates.

ARI means the CA tells us when to renew. We check it multiple times a day. Your next mass revocation event? Just another boring Tuesday.

Nothing to configure.

https://www.certkit.io/blog/acme-ari-and-6-day-certificates #PKI #infosec

ACME ARI support and 6-day certificates

CertKit now polls Let's Encrypt multiple times a day to check when each certificate should renew. That means mass revocations happen automatically, without you doing anything. We also added support for 6-day certificates for environments where 90 days isn't short enough.

CertKit SSL Certificate Management

RE: https://newsie.social/@ProPublica/116205120279539801

This is why scams are on the rise.

Related reminder: Yelp, BBB, Google Maps, etc. are all pay-to-win. Posting reviews on those sites makes THEM money! And it exposes you to legal risk, while you get nothing in return. Skeezy companies just pay for fake reviews or directly pay a bribe to the review sites.

Like voting, this is another problem that could be solved with #pki, if only lawmakers could grasp technology.

#reviews #complaints #consumeraffairs #consumerprotections #cfpb

Your cert renewed. The old one is still serving.

LinkedIn renewed 10 days before expiry. It never deployed.

Most automation catches "forgot to renew." Nobody verifies the new cert is what the server is actually sending.

https://www.certkit.io/blog/how-to-verify-certificate-renewal #PKI #TLS

How to verify certificate renewal actually worked

Certbot ran. The logs show success. Exit code 0. LinkedIn found out the hard way that renewed and deployed are not the same thing. The verify step is the part of certificate automation nobody builds until after the outage.

CertKit SSL Certificate Management
@HaWeCom Tja, die Leute sollen wohl wieder kriminell werden, damit die Statistik einen Grund für's Aufrüsten im Bereich Innenministerium hergibt. Wenn einer am Boden liegt. muss man ja nachtreten können.
Ich interpretiere aus der #PKI #polizeikriminalstatistik bereits seit Corona ansteigende Armutskriminalität (Taten aus Verzweiflung, die nicht lohnen, so etwas wie Ladendiebstahl).

@Lucseleventje @Marloezovic en #yivi zouden verzekeraars, banken en #odido achtigen ook kunnen gebruiken in plaats van het opslaan overal en nergens van paspoorten en rijbewijzen .
Opslaan aantal soorten gevoelige gegevens hoeft technisch niet meer met yivi! Als er dan een hack komt zoals bij #odido is er veel minder impact voor betrokken burgers.

Moet wel de wet worden aangepast. Opslaan paspoort en is gegevens mag niet meer: #pki based bewijs is immers voldoende (yivi achtig cryptografische ondertekening is het zo goed bewijs van identiteit 🫆, zo niet veel beter want automatiseerbaar)
@barbarakathmann @bert_hubert
#privacy #ransomeware #weerbaarheid #odidohack

Embedded systems security engineer / cryptographer open to contracts or permanent roles. Based in Lausanne, CH.

Background in embedded crypto libraries, PKI, smartcard middleware, software security research.

For contracts: direct preferred, remote-friendly. For permanent: Lausanne-commutable or remote.

Languages: English, French, some German.

DM or email preferred.

#cryptography #embeddedsystems #PKI #infosec #contractor #hiring #FediHire #fedihireme #fedihired #jobsearch #rust