Knowledgebase

Certificate Security and Transparency Print

  • internet, ssl, security, domain, dns, hacked, downtime, guide
  • 0

Preventing misissuance.

WHAT MISISSUANCE IS

A certificate issued for a name to someone not entitled to it.

WHY IT MATTERS

It permits interception with a certificate the client trusts.

WHAT CERTIFICATE TRANSPARENCY IS

A public log of every certificate issued, which browsers require.

WHAT IT ENABLES

Detecting certificates issued for your names that you did not request.

WHAT TO DO

Monitor the logs for your domains.

WHAT CERTIFICATE AUTHORITY AUTHORISATION RECORDS DO

Declare in DNS which authorities may issue for your domain.

WHAT THAT PREVENTS

Issuance by other authorities, where they honour it.

WHAT TO PUBLISH

Those records, for every domain.

WHAT PINNING DOES

Restricts which certificates a client accepts, beyond the chain.

WHY IT IS NOW RARE ON THE WEB

It caused outages when certificates changed, and browsers withdrew support.

WHERE IT REMAINS

Applications, where the operator controls both ends.

WHAT TO PROTECT MOST

Private keys.

WHERE TO KEEP THEM

Restricted, never in version control, never transmitted insecurely.

WHAT TO DO IF ONE IS EXPOSED

Revoke and reissue, assuming compromise.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot