Every time something positive is published about SSL and encryption,such as Google’s recent decision making use of https encryption a favorable rating factor for a website, or n…
PKI Consortium blog
Posts by tag Revocation
Short answer: Government CAs can still be considered “trusted third parties,” provided that they follow the rules applicable to commercial CAs. Introduction On July 8 Google ann…
With the announcement of the Heartbleed bug and the resulting need to revoke large numbers of SSL certificates, the topic of certificate revocation has, once again, come to the …
The recent Heartbleed issue has reawakened interest in SSL certificate revocation (see Adam Langley’s [blog][1], Larry Seltzer’s articles [here][2] and [here][3], and Steve Gibs…
The Heartbleed bug spurred server administrators worldwide to work closely with Certification Authorities (CAs) in rekeying and reissuing potentially vulnerable SSL certificates…
CA Security Council (CASC) members Trend Micro, Go Daddy, and Symantec participated in a discussion panel at the 2014 RSA Conference in San Francisco on February 24 entitled “Ne…
After the CASC’s [previous][1] letter addressing ICANN’s proposal to delegate nearly 2000 new gTLDs for use on the public Internet, ICANN identified and initiated an extensive s…
Internet Surveillance The big news at [IETF 88 in Vancouver][1] was the technical plenary on [Hardening the Internet][2] which discussed the issue of pervasive surveillance. Per…
Have you ever wondered why your web server certificate has a “chain” of other certificates associated with it? The main reason is so that browsers can tell if your certificate w…
If you are reading this post you are probably already familiar with the use of digital certificates and SSL even if you may not be familiar with the history. Before exploring th…

