The Long Life Certificate – Why It Doesn’t Exist Why is certificate expiration even necessary? Wouldn’t it be better if I could just buy a certificate with a long life before ex…
PKI Consortium blog
Posts by tag Vulnerability
Always On SSL should be deployed to prevent the “Not secure” warning Website owners who do not secure their website with an SSL/TLS certificate will have to rethink their online…
A team of researchers has announced a vulnerability with [SSL 2.0][1] called D ecrypting R SA with O bsolete and W eakened e N cryption; otherwise known as [DROWN][2]. SSL 2.0 i…
Part 1 of this blog post discussed browser security indicators and how to avoid getting warnings about mixed content on your website. (Mixed content leaves a door open that allo…
Over the past several years there has been increased discussion about deprecating HTTP and making HTTPS the default protocol for the World Wide Web. (HTTP stands for “HyperText …
On January 1, 2016, the public trust certification authorities (CAs) will stop issuing SHA 1 signed SSL/TLS certificates. What will happen? Will all websites using SHA 1 fail? N…
Looking Back at 2015 A number of new tactics proved 2015 was no exception to an active year defending against ever increasing security issues. Vendors found new and creative way…
OpenSSL has announced a high severity vulnerability, CVE 2015 1793 which will require an upgrade to some OpenSSL installations. The vulnerability was discovered by Google person…
Recently, we read about lots of SSL/TLS related vulnerabilities found in mobile apps, which should come as no surprise. We were warned about this back in 2012 (see [these][1] [s…
Another flaw has been found in the basic encryption algorithms that secure the Internet. This flaw, named the Logjam attack by its discoverers (researchers from various universi…

