(10 votes, average: 4.90 out of 5)

Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw

A critical vulnerability in the SSL.com domain validation process allowed unauthorized parties to get the certificates on behalf of you or your organisation. SSL.com is one of the famous Certificate Authorities (CA) trusted by all major browsers. This Vulnerability is reported by security researchers; in their demonstration, they showed how…
(12 votes, average: 4.92 out of 5)

What’s the Difference Between Multi-Domain & Wildcard SSL Certificates?

What is Wildcard SSL? A Wildcard SSL certificate is a unique SSL certificate that protects a single domain and all its subdomains. In contrast to standard SSL certificates that secure only one domain, a Wildcard SSL certificate employs a wildcard character—an asterisk, *—in the domain name, enabling encryption for countless…
(13 votes, average: 5.00 out of 5)

The End of WHOIS-Based DCV Methods: What You Need to Know and How to Transition

Because of critical weaknesses in the WHOIS system, the CA/Browser Forum has required that WHOIS-based Domain Control Validation (DCV) methods be retired. This change applies to all CAs, and there was a broader effort to improve the security and reliability of publicly trusted SSL/TLS certificates. To be compliant, all big…
(17 votes, average: 4.94 out of 5)

DigiCert Elevates Industry Standards with New Open-Source DCV Library

DigiCert confidently continues to improve validations for digital certificates. At this time, it keeps up with new ideas and the new rules set by the industry for this much-needed release. Its latest development is an open-source library on Domain Control Validation. This makes it easier, more automated, and more dependable…
(16 votes, average: 5.00 out of 5)

Apple’s Proposal to Shorten SSL/TLS Certificate Lifespans to 45-Days by 2027

In a recent industry shift, Apple finally dropped draft proposal details for shortening the maximum public SSL/TLS certificates to 45 days by 2027. The announcement, made on October 9, 2024, as part of the CA/Browser Forum’s Face-to-Face meeting, received a positive boost from Sectigo, a significant player in the digital…
(16 votes, average: 4.94 out of 5)

DigiCert Revoked 83,000+ SSL Certificates Due to Domain Validation Issue

Certificate authority (CA) DigiCert has stated that they will invalidate many SSL/TLS certificates due to a critical domain validation flaw. This flaw, which affects over 83,000 certificates, is a serious issue as it undermines the process of verifying the rightful holders of domain names, a crucial aspect of SSL/TLS certificates.…
(19 votes, average: 4.95 out of 5)

Google Chrome to Block Entrust Certificates Starting November 2024

Google has recently shared that its Chrome web browser will now block web destinations relying on certificates from Entrust starting from approximately November 1, 2024. This action has been taken following several years of Entrust non-compliance and security challenges that the company has not been able to handle well. As…
(38 votes, average: 4.18 out of 5)

Comodo PositiveSSL vs RapidSSL: Difference Explained

RapidSSL and Comodo PositiveSSL are renowned companies that will assist you in quickly narrowing down the choices you make if you’re looking for the best and most affordable SSL certificate for your website. These certificates offer industry-standard encryption, appealing site seals, and comprehensive warranties at the lowest prices for SSL…
(18 votes, average: 5.00 out of 5)

What Is Certificate Pinning? How does Certificate Pinning Work?

What Is Certificate Pinning? Certificate pinning is a security measure where the client application checks against a copy known as the certificates the server is using. On the other hand, this cross-platform server application can serve as a cert pinning client as it embeds the certificate issued to the server…
(17 votes, average: 5.00 out of 5)

Free vs. Paid SSL: The Hidden Dangers of Free SSL Certs

To ensure secure connections between users and websites, organizations prioritize using SSL certificates, as it’s pretty evident that a website secured with an SSL certificate assures visitors that it’s safe to use. When it comes to obtaining SSL certs, there’s often a debate about whether to opt for free or…
(16 votes, average: 5.00 out of 5)

What is mTLS Authentication (Mutual TLS)?

What is mTLS? mTLS, which stands for Mutual Transport Layer Security, is a security protocol that can be used between two client and server applications to enable the encryption of their communication sessions while they access each other over a network, such as the internet. It is a further development…
(16 votes, average: 5.00 out of 5)

HSTS Explained – Detailed Guide on HTTP Strict Transport Security

What is HSTS (HTTP Strict Transport Security)? HTTP Strict Transport Security is commonly referred to by the acronym HSTS. Websites utilize this technique to indicate that they should only be viewed over secure connections (HTTPS). A browser must reject all HTTP connections and stop users from accepting unsafe SSL certificates…
(15 votes, average: 4.80 out of 5)

What is a Fully Qualified Domain Name?

Summary A domain name is a distinct, human-readable Internet address for a website. Knowing what a fully qualified domain name (FQDN) is crucial when working with domains and domain name system (DNS) management. A fully qualified domain name (FQDN) is a component of a URL or universal resource locator. As…
(18 votes, average: 4.94 out of 5)

WHAT IS SSL, TLS & HTTPS? [Explanation to Difference]

SSL, TLS, and HTTPS are unique combinations that work together to protect sensitive information on the Internet. Understanding TLS, SSL, and HTTPS becomes essential if you use the most advanced encryption technologies to protect website content. Internet connections that are encrypted, or “secure,” are associated with HTTPS, SSL, and TLS.…
(18 votes, average: 5.00 out of 5)

What are Certificate Outages? How to Avoid SSL Certificate Outages with ACME?

Most people might now know about digital identity certificates, but they notice when organizations don’t handle them well. Suppose someone tries to access your organization’s website online, but the website suddenly stops working. Firstly, they simply refresh the page and try again, but nothing happens. It becomes frustrating, right? This…