Working Groups

Members

The PKI Consortium brings together leading organizations committed to trustworthy digital identities and secure communication.

Browse all members →

PKI Consortium blog

Posts by tag OpenSSL

OpenSSL

Always-On SSL

There is no doubt that content owners and publishers have a duty to encourage trust and the confidence during internet usage by adopting security best practices. If a customer b…

Vulnerability

A team of researchers has announced a vulnerability with [SSL 2.0][1] called D ecrypting R SA with O bsolete and W eakened e N cryption; otherwise known as [DROWN][2]. SSL 2.0 i…

Looking Back at 2015 A number of new tactics proved 2015 was no exception to an active year defending against ever increasing security issues. Vendors found new and creative way…

OpenSSL has announced a high severity vulnerability, CVE 2015 1793 which will require an upgrade to some OpenSSL installations. The vulnerability was discovered by Google person…

Recently, we read about lots of SSL/TLS related vulnerabilities found in mobile apps, which should come as no surprise. We were warned about this back in 2012 (see [these][1] [s…

Looking Back at 2014 End of 1024 Bit Security In 2014, the SSL industry moved to issuing a minimum security of 2048 bit RSA certificates. Keys smaller than 2048 are no longer al…

Vulnerability

In October 2014, [Google announced POODLE][1], an SSL 3.0 protocol attack. To bring you up to speed, the [SSL/TLS protocol][2] is the most important and popular security protoco…

Recent revelations from Edward Snowden about pervasive government surveillance have led to many questions about the safety of communications using the SSL/TLS protocol. Such com…

Mixed Content

There is no doubt that content owners and publishers have a duty to encourage trust and the confidence during internet usage by adopting security best practices. If a customer b…