-
Podcast Feb 22, 2021
Root Causes 151: What Is Rustls?
Rustls is an important emerging alternative to OpenSSL. We discuss the Rust programming language, designed with security in mind from the ground up.
-
Blog Post Feb 01, 2021
I am excited to share that Sectigo has received the 2020 Global Competitive Strategy Leadership Award from Frost & Sullivan in recognition of our PKI portfolio. The market research leader based the award on its recent analysis of the global transport layer security (TLS) certificates market and specifically cited Sectigo’s ‘easy-to-use management platform’ and use of automation and IETF standards-based integrations among its reasons for bestowing the award.
-
Podcast Jan 29, 2021
Root Causes 145: Google Chrome to Distrust CA Camerfirma
Google has announced distrust for Spanish public CA Camerfirma in Chrome build 90. We explain the reasons for (and implications of) this decision.
-
Podcast Jan 26, 2021
Root Causes 144: Whatever Happened to the Green Address Bar?
In recent years the EV SSL "green address bar" has shrunk and evenually disappeared. We walk you through how that came to be.
-
Podcast Jan 18, 2021
Root Causes 142: Removing Street and Postal Code from Public Certs
On March 1 Sectigo will remove street address and postal/zip code information from its public certificates of all types. Our hosts explain why.
-
Notification Jan 11, 2021
As of March 1, 2021 Sectigo will remove street address and zip/postal code information from all public certificates.
-
Podcast Jan 11, 2021
Root Causes 141: The Case for Shorter Certificate Lifespans
Our hosts are joined by guest Nick France to discuss the benefits of shorter certificate lifespans for both public and private CAs.
-
Podcast Jan 07, 2021
Root Causes 140: SSL Attacks Using BGP (Border Gateway Protocol)
BGP controls traffic routing on the internet. BGP attacks could help improperly obtain DV certificates. We explain these attacks and what to do about them.
-
Podcast Jan 04, 2021
Root Causes 139: Exposed Private Keys in CSR Submissions
Sometimes subscribers accidentally include the private key along with CSR submissions. Our hosts break down this phenomenon and its implications.
-
Blog Post Dec 21, 2020
The SolarWinds attack touches on digital certificates and identity authentication in some important ways.
-
Podcast Dec 21, 2020
Root Causes 137: SolarWinds Supply Chain Attack and Digital Identity
The SolarWinds supply chain attack i includes unusual manipulations of digital identity and certificates. We explore these aspects of the attack.
-
Podcast Dec 14, 2020
Root Causes 135: The Heartbleed Vulnerability
2014's Heartbleed vulnerability made it possible to steal private keys directly from web servers, requiring certificate replacement by the millions.