Short answer: Government CAs can still be considered “trusted third parties,” provided that they follow the rules applicable to commercial CAs. Introduction On July 8 Google ann…
PKI Consortium blog
Posts by tag Chrome
The recent Heartbleed issue has reawakened interest in SSL certificate revocation (see Adam Langley’s [blog][1], Larry Seltzer’s articles [here][2] and [here][3], and Steve Gibs…
The Heartbleed bug spurred server administrators worldwide to work closely with Certification Authorities (CAs) in rekeying and reissuing potentially vulnerable SSL certificates…
CA Security Council (CASC) members Trend Micro, Go Daddy, and Symantec participated in a discussion panel at the 2014 RSA Conference in San Francisco on February 24 entitled “Ne…
In a previous post titled [Getting the Most Out of SSL Part 2][1] , we touched on the recommendation that Web servers be configured to prefer Transport Layer Security (TLS) vers…
The current browser certification authority (CA) trust model allows a website owner to obtain its SSL certificate from any one of a number of CAs. That flexibility also means th…
The latest version of the Firefox Web browser from Mozilla was released on August 6th with a great new security feature called a “mixed content blocker”. In a nutshell, this fea…

