Public Key Infrastructure (PKI)


All blog articles on the subject of Public Key Infrastructure (PKI)
Jan Weil

Published on 21.11.2020 in the category Communication Security published.

OCSP Stapling: The Good, the Bad, and the Ugly

When hackers have compromised a certificate, the Online Certificate Status Protocol (OCSP) with the Must-Staple extension is often the last line of defense for your own protection. (read more)


Andreas Sperber

Published on 21.07.2017 in the category Communication Security published.

Using HTTP Public Key Pinning Securely

Public Key Pinning restores trust in the PKI. However, this powerful method must be used correctly, otherwise serious dangers may arise. (read more)


Andreas Sperber

Published on 31.05.2017 in the category Communication Security published.

Trust is Good. Verification is Better.

Andreas Sperber spoke about trust problems in PKIs at the 17th GPN. With "Trust is Good. Verification is Better.", he calls on service providers to take action. (read more)


Andreas Sperber

Published on 17.04.2017 in the category Communication Security published.

Certificate Transparency – Transparency in the Certificate Jungle

Certificate Transparency is a system for monitoring certificates. For Google Chrome, it has been mandatory since October 2017. We report on what needs to be considered. (read more)


Andreas Sperber

Published on 21.03.2017 in the category Communication Security published.

Why Do We Trust Certificate Authorities?

Certificate authorities are an essential component of today's World Wide Web. We place great trust in them despite worrying incidents. (read more)


Armin Harbrecht

Published on 19.10.2016 in the category Web Application Security published.

HTTPS on the Rise - Why everyone must switch their site to HTTPS in 2017

Encrypted communication via HTTPS was long only for highly secure web applications. Soon, however, Google will penalize unencrypted websites. (read more)