4 ms·
1) monitor the complete certificate chain 2) indeed have a backup certificate ready (might be non EV), this is especially a must if you use HSTS [1] (which you
by bwblabs 12y ago
1) monitor the complete certificate chain
2) indeed have a backup certificate ready (might be non EV), this is especially a must if you use HSTS [1] (which you should use BTW) it is actually a (low priority) government recommendation (B5-6) in The Netherlands [2], but that might have something to do with the government heavily using DigiNotar which got compromised and had it root certificates revoked by Microsoft which caused some communication issues..
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[2] https://www.ncsc.nl/binaries/nl/dienstverlening/expertise-advies/kennisdeling/whitepapers/ict-beveiligingsrichtlijnen-voor-webapplicaties/1/ICT%2Bbeveiligingsrichtlijnen%2Bvoor%2Bwebapplicaties%2B%2B%2Bdeel%2B1%2B%2Bleesversie%2B.pdf https://www.ncsc.nl/binaries/nl/dienstverlening/expertise-ad... (in Dutch)
- peterwwillis 12y agoIf you want to verify the complete chain or see if any of it is expired, I wrote some tools that'll do just that. It uses a pre-existing directory of CA certs (which you can generate with an included Makefile and cacert.pem) and downloads intermediaries. https://github.com/psypete/public-bin/tree/public-bin/src/networking/check-ssl https://github.com/psypete/public-bin/tree/public-bin/src/ne...