3 ms·
> My greatest pain with certificates and especially the X509 standard is that it‘s so large / loosely designed, it‘s hard to call it a standard at all. X509 is
by 0x00cl 2y ago
> My greatest pain with certificates and especially the X509 standard is that it‘s so large / loosely designed, it‘s hard to call it a standard at all. X509 is more of a bucket you can almost drop anything in.
I recently wrote a blog post[1] about the limits of TLS certs and from what I understood of X.509 is more of a framework and standards or applications can use it to define their certificates such as RFC 5280[2] which is the standard that defines their usage on the Internet.
[1] https://0x00.cl/blog/2024/exploring-tls-certs/ https://0x00.cl/blog/2024/exploring-tls-certs/
[2] https://www.rfc-editor.org/rfc/rfc5280 https://www.rfc-editor.org/rfc/rfc5280