Entrust's monthly SSL review covers SSL discussions "” recaps news, trends and opinions from the industry. Entrust and CA Security Council Entrust Identity ON discussed: Logjam Attack and Diffie-Hellman CA Security Council discussed: Practical Steps to Counter the Logjam Attack Hot Topics & ...
As we move in 2015, you will start to see Certificate Transparency deployed on EV SSL certificates. Google has required that as of January 2015, all EV SSL certificates be publicly logged to retain their EV status. All current EV SSL certificates will be white listed for the Chrome browser. Google...
Over the last few years, we’ve witnessed publicly trusted SSL certificates issued to domain names that were not authorized. These miss-issuances are typically caused by attackers or simply a mistake by a certification authority (CA). Miss-issuance has been detected in a brute-force manner. Typicall...
OCSP Must-Staple
This post was originally published by on the CA Security Council blog. With the announcement of the Heartbleed bug and the resulting need to revoke large numbers of SSL certificates, the topic of certificate revocation has, once again, come to the fore. There have been many issues with how revocat...
A quick look at our world today reveals that the need for mobile security has never been greater. After all, the number of activated mobile devices has actually surpassed the population of our planet. For the people who use them — which is just about everybody — such devices permeate every aspect...
We have discussed the SHA-1 deprecation policy and why you should move to SHA-2. The certification authorities (CAs) have provided methods to have your certificates issued and signed using a SHA-2 hashing algorithm. As we move ahead, you will see the CAs changing the default signing algorithm from ...