Preventing misissuance.
WHAT MISISSUANCE IS
A certificate issued for a name to someone not entitled to it.
WHY IT MATTERS
It permits interception with a certificate the client trusts.
WHAT CERTIFICATE TRANSPARENCY IS
A public log of every certificate issued, which browsers require.
WHAT IT ENABLES
Detecting certificates issued for your names that you did not request.
WHAT TO DO
Monitor the logs for your domains.
WHAT CERTIFICATE AUTHORITY AUTHORISATION RECORDS DO
Declare in DNS which authorities may issue for your domain.
WHAT THAT PREVENTS
Issuance by other authorities, where they honour it.
WHAT TO PUBLISH
Those records, for every domain.
WHAT PINNING DOES
Restricts which certificates a client accepts, beyond the chain.
WHY IT IS NOW RARE ON THE WEB
It caused outages when certificates changed, and browsers withdrew support.
WHERE IT REMAINS
Applications, where the operator controls both ends.
WHAT TO PROTECT MOST
Private keys.
WHERE TO KEEP THEM
Restricted, never in version control, never transmitted insecurely.
WHAT TO DO IF ONE IS EXPOSED
Revoke and reissue, assuming compromise.