CA's, X509, GAFAM and SSL/TLS, Letsencrypt, a story
-
Found a nice video "Everything you learned about SSL is deprecated - Todd Gardner - NDC Toronto 2026" that recaps about how 'https' became a thing.
A nice recap about SSL that became TLS, CAs and browsers.
edit : and why the 'TTL' of a certificate becomes shorter and shorter.What I make of it : The buried subject is DNS. (It's always DNS).
As soon as you, me, we all, those who expose TLS services on the net or locally, use secured DNS or DNSSEC, not to be mistakes with encrypted DNS, everybody can host their own, self created 'CA' certificate. Our browser can trust it, as it knows where it came from.
I repeat, with other words : if DNS is forwarded, the 'secure' part breaks ^^Another thought : the final business goal of Letsencrypt (and others now) : If they do their work well, they, all of them, as a CA, can close down business as not needed anymore.
Privacy Policy · Cookie Policy