Andrew Ayer's Avatar

Andrew Ayer

@agwa.name.bsky.social

Bootstrapped founder of SSLMate (https://sslmate.com). Making SSL certificates easier and doing #WebPKI and #CertificateTransparency research on the side. Blog: https://www.agwa.name He/him

139 Followers  |  65 Following  |  1 Posts  |  Joined: 30.03.2024  |  1.2871

Latest posts by agwa.name on Bluesky

Preview
ca-certificates bundle incorrectly excludes root CAs with CKA_NSS_SERVER_DISTRUST_AFTER (#6) Β· Issues Β· alpine / ca-certificates Β· GitLab The build script in ca-certificates incorrectly omits CA roots with a "DistrustAfter" attribute. See this fix in curl: https://github.com/curl/curl/commit/448df98d9280b3290ecf63e5fc9452d487f41a7c#diff...

Turns out Alpine Linux has a copy of the same script from curl! I've raised an issue in their issue tracker: gitlab.alpinelinux.org/alpine/ca-ce...

07.01.2025 10:16 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
The Entrust Distrust Will Be More Disruptive Than Intended Non-browser clients don't properly handle the Distrust After date

I recently investigated how the Entrust distrust would be unintentionally disruptive to non-browser clients: sslmate.com/blog/post/en...

Good news since then: curl has fixed their CA bundle generator, a fix is pending for mkcert.org, and python-certifi is pausing releases until mkcert is fixed!

25.11.2024 21:02 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

@agwa.name is following 20 prominent accounts