Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    CA's, X509, GAFAM and SSL/TLS, Letsencrypt, a story

    Scheduled Pinned Locked Moved ACME
    1 Posts 1 Posters 97 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG Offline
      Gertjan
      last edited by Gertjan

      Found a nice video "Everything you learned about SSL is deprecated - Todd Gardner - NDC Toronto 2026" that recaps about how 'https' became a thing.

      A nice recap about SSL that became TLS, CAs and browsers.
      edit : and why the 'TTL' of a certificate becomes shorter and shorter.

      What I make of it : The buried subject is DNS. (It's always DNS).
      As soon as you, me, we all, those who expose TLS services on the net or locally, use secured DNS or DNSSEC, not to be mistakes with encrypted DNS, everybody can host their own, self created 'CA' certificate. Our browser can trust it, as it knows where it came from.
      I repeat, with other words : if DNS is forwarded, the 'secure' part breaks ^^

      Another thought : the final business goal of Letsencrypt (and others now) : If they do their work well, they, all of them, as a CA, can close down business as not needed anymore.

      No "help me" PM's please. Use the forum, the community will thank you.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
      Privacy Policy · Cookie Policy