Publié par : pintejp | novembre 23, 2015

Changes in the TLS certificate ecosystem, part 1

TLS certificates are the basis for most encrypted connections on the internet and for HTTPS in particular. This system, where certificate authorities issue certificates for a fee to associate the ownership of a domain with the key contained in the certificate, has gotten a bad reputation over the years. But a lot has changed recently to improve the security of the TLS certificate ecosystem. New technologies like HTTP Public Key Pinning and Certificate Transparency allow detecting and sometimes preventing the use of rogue certificates—and browser vendors have become much less willing to accept misbehavior by certificate authorities.

https://lwn.net/Articles/663875/


Laisser un commentaire

Catégories