3 ms·
Ugh TLS certificates are such flaming garbage. There is zero reason for them to be in a machine-first protocol like ASN. Here we are with billions of computers
by firstlink 3y ago
Ugh TLS certificates are such flaming garbage. There is zero reason for them to be in a machine-first protocol like ASN. Here we are with billions of computers spewing human-first protocols like JSON at each other and we can't even use it for human-only info like TLS certificate fields.
But of course the complete incomprehensibility of TLS certs is a feature, not a bug: creating and signing your own is so difficult and arcane that it generates business for certificate vendors, even for certs for private use.
- 8organicbits 3y ago> even for certs for private use. This has been a concern of mine. Paired with incompatibility in clients[1] it's easy to mess up. I'm building a service[2] and related tooling that makes it easier to use public CAs for private use. I'm in early stages, but feedback has been good so far. [1] https://alexsci.com/blog/name-non-constraint/ https://alexsci.com/blog/name-non-constraint/ [2] https://alexsci.com/blog/improve-https-1/ https://alexsci.com/blog/improve-https-1/