Hacker News with Generative AI: Certificates

Six day and IP address certificate options in 2025 (letsencrypt.org)
This year we will continue to pursue our commitment to improving the security of the Web PKI by introducing the option to get certificates with six-day lifetimes (“short-lived certificates”). We will also add support for IP addresses in addition to domain names. Our longer-lived certificates, which currently have a lifetime of 90 days, will continue to be available alongside our six-day offering.
Certificate Profile Selection (Let's Encrypt) (letsencrypt.org)
We are excited to announce a new extension to Let’s Encrypt’s implementation of the ACME protocol that we are calling “profile selection.” This new feature will allow site operators and ACME clients to opt in to the next evolution of Let’s Encrypt.
Let's Encrypt to end OCSP support in 2025 (scotthelme.co.uk)
Well, the writing has been on the wall for some years now, arguably over a decade, but the time has finally come where the largest CA in the World is going to drop support for the Online Certificate Status Protocol.
Short-Lived Certificates Coming to Let's Encrypt (schneier.com)
Let's Encrypt: 2024 Annual Report [pdf] (abetterinternet.org)
ICP-Brasil: Mis-issued certificate (mozilla.org)
ICP-Brasil: Mis-issued certificate
A Brazilian CA trusted only by Microsoft has issued a certificate for google.com (agwa.name)
Just want simple TLS for your .internal network? (github.com/nh2)
Safely shareable TLS root CA for .internal networks using Name Constraints
Avoiding downtime: modern alternatives to outdated certificate pinning practices (cloudflare.com)
In today’s world, technology is quickly evolving and some practices that were once considered the gold standard are quickly becoming outdated.
iOS 18 breaks IMAPS self-signed certs (apple.com)
Nvd.nist.gov cert expired yesterday and uses HSTS (nist.gov)
All I Know About Certificates – Certificate Authority (pixelstech.net)
DigiCert Revocation Incident (CNAME Domain Validation) (digicert.com)
Intent to end OCSP service (letsencrypt.org)
Telekom Security: Revocation delay for TLS certificates (mozilla.org)
Telekom Security: Revocation delay for TLS certificates (mozilla.org)
Letsencrypt Supports Wildcard Certificates (letsencrypt.org)
Microsoft forgot to renew their Office CDN certificate (reddit.com)
Entrust Certificate Distrust (googleblog.com)
Build a tiny certificate authority for your homelab (smallstep.com)
We ensure Cloudflare customers aren't affected by LE's certificate chain change (cloudflare.com)