Hacker News new | past | comments | ask | show | jobs | submit login
Everything You Never Wanted to Know about PKI but Were Forced to Find Out [pdf] (auckland.ac.nz)
27 points by doodlesdev on May 30, 2023 | hide | past | favorite | 3 comments



Seems to be from the early 2000s, although not dated. Can anyone with knowledge on PKI shine light on if it's still relevant? Has much changed in the last 20 years?


It looks to be very relevant. CRLs are more frequently checked now due to bandwidth and compute becoming much cheaper. OCSP is a common solution for larger CAs. Cross-signing is becoming more common, and it still is a mess with clients validating it in different ways. Let's Encrypt used cross-signing when they rolled over to their own ISRG X1 root. There's a CA/Browser Forum group which defines rules and standards for browsers to trust public CAs and all major browsers use them to determine which roots to trust. Certificate Transparency logs are also a new development which is like a blockchain of issued certificates. CA/B Forum requires CT to be implemented by all publicly trusted CAs.


Creation date of PDF is 11/21/2002, 9:08:38 PM




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: