Categories
Computer Tech Security

SSL/TLS Certificate lifetime

The SSL/TLS certificate revocation system (CRL and OCSP) is broken. This is a fact known for a long time by the whole certificate industry. Long-lived certificates that have issues (eg. a certificate that was fraudulently issued), hang around on the Internet for extended periods (currently up to 3 years) potentially causing security and authenticity issues. […]

Categories
Computer Tech Security

Symantec, Google and the SSL Monkey

Some education first PKI or Public Key Infrastructure is a technology that allows website visitors to trust SSL certificates presented by SSL encrypted websites. An example is when you visit your Internet Banking website – you can verify the authenticity of the site by checking the SSL Certificate of the site ( ie. clicking on […]

%d bloggers like this:
x Logo: Shield Security
This Site Is Protected By
Shield Security