Musings about WebPKI and Public Trust
Subscribe
Sign in
Home
Archive
About
Workload Identity: Part 1
What is it? And how does it intersect with WebPKI?
Apr 22
•
Amir
1
September 2024
Ballot removing the WHOIS reliant domain control validation methods
Hi folks,
Sep 16, 2024
•
Amir
Issuance Auditability: Certificate Validation Methods
With great power, comes even greater transparency requirements
Sep 15, 2024
•
Amir
July 2024
Reflections on Entrust's Distrust
What happened, why now, and what does this mean for the future of WebPKI
Jul 1, 2024
•
Amir
6
4
June 2024
Entrust has been distrusted
Announcement: https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html
Jun 27, 2024
•
Amir
4
May 2024
Mozilla: Entrust Issues
What is Entrust's and WebPKI's Future?
May 6, 2024
•
Amir
1
April 2024
Entrust considered harmful - Part 3
Two steps forward, no revokes back
Apr 29, 2024
•
Amir
2
Entrust considered harmful - Part 2
Where Entrust chooses to continue misissuing certificates
Apr 22, 2024
•
Amir
4
Entrust considered harmful - Part 1
A series on harmful pattern of behavior by Entrust
Apr 15, 2024
•
Amir
6
Beyond Distrust, what can a root program do?
Moving away from the binary trust model for CAs and taking small steps to heal the ecosystem
Apr 10, 2024
•
Amir
4
March 2024
Entrust mis-issues a certificate, Refuses To Follow CA/B Rules
Extended Validation certificates are a massive hole in web security
Mar 15, 2024
•
Amir
3
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts