May 2017
- Let's talk about revocation checking, let's talk about you and me.
I have been having a conversation with Melhi at Comodo, this is the most recent post in that series.
- My response, to his response, to my response? or short-lived certificates part 3
The conversation on short-lived certificates and their value continues. In the most recent conversation, we have started to shift from an either or position to one where we explore what is needed to make revocation…
- It is my turn, or short-lived certificates part 2
My response to a recent post suggesting short-lived certificates were intended to remove the need to do revocation seems to have spurred a response from its author.
- How to keep a secret in Windows
Protecting cryptographic keys is always a balancing act. For the keys to be useful they need to be readily accessible, recoverable and their use needs to be sufficiently performant so their use does not slow your…
- Why bother with short-lived certificates and keys in TLS?
There seems to be a lot of confusion and misinformation about the idea of short-lived certificates and keys so I thought I would pen some thoughts about the topic in the hope of providing some clarification.