Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

CertKit

@certkit@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

21 Followers
36 Following
39 Posts
Joined October 27, 2025
Website:
https://www.certkit.io/
Open post
CertKit @certkit@infosec.exchange
· 3mo ago
The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47. Revocation never worked, so the industry is killing long lifespans instead. @toddhgardner@hachyderm.io broke down the why on RunAs Radio. https://runasradio.com/Shows/Show/1041 #SSL #PKI
47 Day Certificates with Todd Gardner
RunAsRadio

47 Day Certificates with Todd Gardner

The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last only 47 days! Todd talks...

3
0
1
0
Open post
CertKit @certkit@infosec.exchange
· 2mo ago
If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. https://www.certkit.io/blog/tls-handshake-explained #TLS #SysAdmin
How the TLS handshake works, and why half of it is gone
CertKit SSL Certificate Management

How the TLS handshake works, and why half of it is gone

Every HTTPS connection starts with a TLS handshake. It's a lot shorter than it used to be because twenty years of attacks removed a lot of insecure steps.

2
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 2mo ago

I spent months telling people not to run their own CA.

Today CertKit ships Private PKI. Running a CA is a job, so we took the job. SSL certs for mTLS, IPs, and internal names, root auto-installed on deploy.

https://www.certkit.io/blog/certkit-private-pki

#PKI

CertKit Private PKI: A private certificate authority without running one yourself
CertKit SSL Certificate Management

CertKit Private PKI: A private certificate authority without running one yourself

I spent months telling you not to run your own certificate authority. Today CertKit ships Private PKI. Both things are true, because the job was the problem, and we took the job.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 2mo ago
Let's Encrypt issued its last client auth cert on July 8. They're 90-day certs, so the last expire in early October with no renewal behind them. If you run mTLS on public certs, that's the window. https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing
Public mTLS client-auth certificates stop renewing in October
CertKit SSL Certificate Management

Public mTLS client-auth certificates stop renewing in October

Chrome's root program is pulling mTLS client authentication out of the public web PKI. Let's Encrypt got there first, and the last client certificates they issued expire in early October.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 4mo ago

Let's Encrypt drops cert lifetimes to 45 days by Feb 2028, a year early.

CertKit now supports their TLS Server profile, so you can issue 45-day certs today and test your automation before the deadline.

https://www.certkit.io/blog/managed-accounts-for-msps

#LetsEncrypt #SSL

Managed accounts for MSPs, plus 45-day certificates you can use today
CertKit SSL Certificate Management

Managed accounts for MSPs, plus 45-day certificates you can use today

MSPs can now stand up fully-managed CertKit accounts for their clients, deploy certificates and agents, then hand over the keys. We also added support for Let's Encrypt's TLS Server profile, so you can issue 45-day certificates right now.

2
0
1
0
Open post
CertKit @certkit@infosec.exchange
· 2mo ago
A 47-day SSL certificate is not a shorter version of the same job. It is a different job. Once a year, a person can renew it. Eight times a year, they cannot. Issuance was solved. Distribution is the hard part. https://runasradio.com/Shows/Show/1041 #SSL #SysAdmin
47 Day Certificates with Todd Gardner
RunAsRadio

47 Day Certificates with Todd Gardner

The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last only 47 days! Todd talks...

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 3mo ago
CertKit now deploys SSL certificates to Microsoft Exchange, SQL Server, SSRS, and Citrix NetScaler. Exchange is auto-detected. No script editing. Template, certificate, done. https://www.certkit.io/blog/easy-mode-certificate-deployments #SSL #sysadmin
Certificate deployments just got an easy mode
CertKit SSL Certificate Management

Certificate deployments just got an easy mode

The old deployment flow expected you to know certificate formats, store locations, and your way around a script editor. The new one asks for a template, a name, and a certificate. That's it.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 4mo ago

Managing SSL certs for clients? New: managed accounts. An MSP sets up the client's CertKit account, deploys certs and agents, then hands it over.

Client owns it. You keep audited support access.

https://www.certkit.io/blog/managed-accounts-for-msps

#MSP #SSL

Managed accounts for MSPs, plus 45-day certificates you can use today
CertKit SSL Certificate Management

Managed accounts for MSPs, plus 45-day certificates you can use today

MSPs can now stand up fully-managed CertKit accounts for their clients, deploy certificates and agents, then hand over the keys. We also added support for Let's Encrypt's TLS Server profile, so you can issue 45-day certificates right now.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago

CertKit Agent 1.8: Windows Certificate Store, Java Keystore, and RDP auto-detection.

We also shipped a retro MS-DOS confirmation dialog on April Fools Day. It is fully keyboard-compatible.

https://www.certkit.io/blog/agent-1.8 #CertificateManagement #PKI

CertKit Agent 1.8: Windows RDP, Windows Certificate Store, and Java keystores
CertKit SSL Certificate Management

CertKit Agent 1.8: Windows RDP, Windows Certificate Store, and Java keystores

Agent 1.8 closes the last gaps in Windows and Java certificate deployment. Write directly into the Windows Certificate Store, auto-detect Remote Desktop and Remote Gateway, drop JKS files for legacy Java applications, and use automatic variables in your update commands. Also: we shipped a retro MS-DOS modal on April Fools Day.

2
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago

Let's Encrypt ran a mass revocation drill on 3 million production certificates in March. No user notifications. They shortened ARI windows to signal an emergency and watched who responded.

Most ACME clients never noticed.

https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation

#PKI #ACME

Let's Encrypt simulated revoking 3 million certificates. Most ACME clients didn't notice.
CertKit SSL Certificate Management

Let's Encrypt simulated revoking 3 million certificates. Most ACME clients didn't notice.

Let's Encrypt ran their first annual mass revocation drill, shortening ARI renewal windows across 3 million production certificates. Here's what happened.

2
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago

A 2024 PKI survey found organizations averaged 3 certificate outages over 24 months. In almost every case, the certificate renewed fine.

Distribution is where it fell apart.

https://www.certkit.io/blog/certificate-distribution-is-the-last-mile #PKI #infosec

Certificate distribution is the last mile nobody solved
CertKit SSL Certificate Management

Certificate distribution is the last mile nobody solved

Certbot solved certificate issuance. It's great at that. The hard part is everything that happens after: getting the certificate file to every server that needs it, in the right format, with the right permissions, and confirming each one is actually serving it. Nobody handed you a solution for that.

2
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

Certificate management has always been a one-person job. CertKit now supports team access: role-based permissions, SAML SSO, MFA, and a weekly digest to keep the whole org in the loop.

https://www.certkit.io/blog/user-management #PKI #infosec

User management, MFA, SSO, and weekly summaries are live
CertKit SSL Certificate Management

User management, MFA, SSO, and weekly summaries are live

CertKit now supports team accounts with role-based access, multi-factor authentication, SAML single sign-on, and a weekly email digest. Here's what shipped and why it matters.

2
0
1
0
Open post
CertKit @certkit@infosec.exchange
· 5mo ago

Security vendors use "trust" as a magic spell. One homepage: 17 uses. I still don't know what they sell. You find out after you fill out a form, take a call, sit through a demo, and receive a market-ecture PDF.

https://www.certkit.io/blog/performative-trust-maximalism

#PKI #infosec

Performative Trust Maximalism
CertKit SSL Certificate Management

Performative Trust Maximalism

Certificate management vendors use the word "trust" so often it stops meaning anything. They also won't tell you what the product does, or what it costs, without a sales call first. These are, I should note, security companies.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago
Replying to
@filippo They may not matter much in volume, but lots of orgs are still tied to the OV/EV certs from legacy CAs. We still need to pull from just about all the CT Logs to get a complete picture for our discovery tool. https://www.certkit.io/tools/ct-logs/
Search Certificate Transparency Logs
CertKit SSL Certificate Management

Search Certificate Transparency Logs

Search the TLS certificate transparency logs to find public certificates issued.This can reveal new subdomains, certificate renewals, or suspicious activity.Great for security monitoring, domain research, and uncovering hidden infrastructure.

1
1
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago

Some organizations have a hard requirement: private keys cannot leave the network perimeter. Third-party cert management has always meant violating that policy.

The CertKit Local Keystore is the fix. Keys stay on your infrastructure. Full automation still works.

www.certkit.io/blog/certkit-keystore

#PKI #CertificateManagement

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

Your cert renewed. The old one is still serving.

LinkedIn renewed 10 days before expiry. It never deployed.

Most automation catches "forgot to renew." Nobody verifies the new cert is what the server is actually sending.

https://www.certkit.io/blog/how-to-verify-certificate-renewal #PKI #TLS

How to verify certificate renewal actually worked
CertKit SSL Certificate Management

How to verify certificate renewal actually worked

Certbot ran. The logs show success. Exit code 0. LinkedIn found out the hard way that renewed and deployed are not the same thing. The verify step is the part of certificate automation nobody builds until after the outage.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

22,000+ incidents in the Verizon DBIR. Man-in-the-middle? Less than 4%, mostly phishing proxies. Not TLS interception.

Forward Secrecy killed "record now, decrypt later." So what actually compromises your connections?

https://www.certkit.io/blog/man-in-the-middle

#cybersecurity #TLS

How likely is a man-in-the-middle attack?
CertKit SSL Certificate Management

How likely is a man-in-the-middle attack?

A stolen TLS private key sounds catastrophic. But thanks to forward secrecy, it can't decrypt recorded traffic. The only thing left is server impersonation, and that requires network position that ranges from "be in the same room" to "be a nation-state." We looked at the data on how often this actually happens.

1
0
1
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

We found a valid DigiCert certificate on a domain we just purchased, issued to someone we've never met. Getting it revoked took 6 emails. 72 hours after confirmed revocation, every browser still trusts it.

https://www.certkit.io/blog/bygonessl-happened-to-us

#InfoSec #CertificateManagement

BygoneSSL happened to us
CertKit SSL Certificate Management

BygoneSSL happened to us

We wrote about BygoneSSL and the 1.5 million domains with certificates owned by someone else. Then we bought certkit.dev and found one on our own domain. A DigiCert certificate, still valid for 98 days, issued to whoever owned this domain before us. Here's what we found, what we tried to do about it, and what happened when we tried to revoke it.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

Most “certificate automation” stops at issuance. That’s how you renew a cert and still serve the old one.

With the CertKit agent, we can now do all three. Renew certs, deploy files, restart services, verify the correct certs run in production.

https://www.certkit.io/blog/certkit-agent

#PKI #DevOps

Introducing the CertKit Agent
CertKit SSL Certificate Management

Introducing the CertKit Agent

CertKit can now deploy certificates directly to your servers. The CertKit Agent is a lightweight service for Linux, Windows, and Docker that detects your software, writes certificates where they need to go, and restarts your services automatically.

1
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 3mo ago
One SSL cert, three servers. Which one generates the private key? Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job. https://www.certkit.io/blog/ssl-certificate-multiple-servers #SSL #PKI
One SSL certificate on multiple servers
CertKit SSL Certificate Management

One SSL certificate on multiple servers

Generating the private key on the server it protects is the textbook answer. Then someone asks for a wildcard, or a second server, and the textbook doesn't have a chapter for that.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029.

Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you.

https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI

Last call on 398-day certificates
CertKit SSL Certificate Management

Last call on 398-day certificates

The bar closes March 15. After that, no CA can serve you a 398-day certificate. If you're still managing commercial SSL certs manually, you have two weeks to grab one last round of full-year runway before the 200-day era begins.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 3mo ago

Let's Encrypt is going post-quantum. I'm not worried about quantum computers.

The real story in Merkle Tree Certificates: smaller handshakes, transparency built in, and even shorter cert lifetimes.

https://www.certkit.io/blog/quantum-is-the-least-interesting-part

#SSL #PKI

Quantum is the least interesting part of quantum certificates
CertKit SSL Certificate Management

Quantum is the least interesting part of quantum certificates

Let's Encrypt just committed to Merkle Tree Certificates for a post-quantum web. I don't think quantum computers are close. The plan is still worth your attention, just not for the reason the headlines give.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 2w ago
Your once-a-year SSL renewal becomes a five-times-a-year renewal on March 15, when public cert lifetimes drop from 200 days to 100. At 47 days, twelve. Oct 6, live with Richard Hicks on automating renewal for Windows servers, VPN, and appliances. Free: https://events.teams.microsoft.com/event/894fa781-9bbd-4eae-9371-86319c13cb08@3b2fb46b-9bbe-41a2-a6fe-a54cbca02865
Microsoft Virtual Events Powered by Teams
events.teams.microsoft.com

Microsoft Virtual Events Powered by Teams

Microsoft Virtual Events Powered by Teams

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 5mo ago

CertKit 1.9: push agent updates from the dashboard, no more logging into every server. Plus Google Trust Store as a second ACME issuer alongside Let's Encrypt.

https://www.certkit.io/blog/agent-1.9

#CertificateManagement #SSL

Remote Agent Updates and Google Trust Store
CertKit SSL Certificate Management

Remote Agent Updates and Google Trust Store

Agent 1.9 adds remote push updates so you can upgrade your entire fleet from the dashboard, plus first-class support for Google Trust Store as an ACME certificate issuer alongside Let's Encrypt.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 5mo ago
Replying to
@adrian@mastodon.offerman.com I share your frustration. I wrote about how the browsers took over the CABrowser forum awhile back. While I don't love that they can mandate things, the CAs were not acting in our best interest either. https://www.certkit.io/blog/47-day-certificate-ultimatum
The 47-Day Certificate Ultimatum: How Browsers Broke the CA Cartel
CertKit SSL Certificate Management

The 47-Day Certificate Ultimatum: How Browsers Broke the CA Cartel

For twenty years, Certificate Authorities ran the perfect protection racket. Then SHA-1 got shattered, Apple went rogue, and certificates went from lasting 3 years to 47 days. This is the story of how browsers broke the CA cartel, and why your manual certificate process is about to become your biggest problem.

0
1
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago

CertKit is out of beta.

600 signups. Real production deployments. A Keystore for keeping private keys on-prem. RDP and RRAS support for Windows shops.

Now there's real pricing — and 40% off forever if you get in before May 31st.

https://www.certkit.io/blog/out-of-beta

#PKI #CertificateManagement

CertKit is out of beta
CertKit SSL Certificate Management

CertKit is out of beta

We launched the beta in July 2025. Over 600 users later, the beta is over. Here's what we built, what we learned, and a thank you to the early adopters who helped make it real.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 4mo ago

PSA: You don't need a private CA for internal SSL certificates.

The CA doesn't connect to your server. It checks a DNS record. Your server can be completely unreachable from the internet.

https://www.certkit.io/blog/private-pki-internal-infrastructure

#PKI #ACME

You probably don't need private PKI for internal infrastructure
CertKit SSL Certificate Management

You probably don't need private PKI for internal infrastructure

Most teams assume internal infrastructure needs a private CA. It doesn't - and skipping it saves you from a maintenance burden that never fully works anyway.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 6mo ago

Mass revocation gives you 24 hours and thousands of certs to replace. ARI (RFC 9773) automates it, but only if your ACME client is always running.

Certbot uses a cron job. acme.sh has no ARI support.

https://www.certkit.io/blog/ari-solves-mass-certificate-revocation

#PKI #TLS

ACME Renewal Information (ARI) solves mass certificate revocation
CertKit SSL Certificate Management

ACME Renewal Information (ARI) solves mass certificate revocation

When a CA has to revoke hundreds of thousands of certificates on a short deadline, email notifications aren't enough. ARI is the protocol that lets the CA tell your client directly: renew now. Here's how it works, and why most ACME clients can't actually respond in time.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 4mo ago

PKI has a term for the leaf-to-root trust chain. It has no term for the series of certs you've been renewing for years.

Certbot calls it a lineage. Nobody else picked it up. At 47-day lifetimes, naming this correctly starts to matter.

https://www.certkit.io/blog/certificate-lineage

#PKI #TLS

Certificate lineage: the concept your tools already use but nobody named
CertKit SSL Certificate Management

Certificate lineage: the concept your tools already use but nobody named

PKI has precise terminology for almost everything. The one thing it never named is the series of certificates you've been renewing for years. Here's what it is, why it matters now, and why your tools already know about it.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 5mo ago
Replying to
@adrian@mastodon.offerman.com If you're looking for ways to handle automation without deploying ACME clients everywhere, opening up ports, and writing elaborate scripting, I'm working on a cost-effective way for smaller shops to do this. I'd love to know what you think. https://www.certkit.io/
CertKit SSL/TLS Certificate Lifecycle Management Software
CertKit SSL Certificate Management

CertKit SSL/TLS Certificate Lifecycle Management Software

CertKit is SSL/TLS certificate lifecycle management software. Discover, issue, renew, and automatically deploy certificates to Linux, Windows, and vendor appliances, then monitor everything so a certificate never expires on you again.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 2mo ago
Replying to
@Scottw@ruby.social Agreed. We baked external monitoring into CertKit from the start because you can never be sure.
0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 4mo ago

Compliance audits ask who touched your certificates, when, and why.

CertKit now captures every certificate action with timestamps and user attribution. Importance flags let you cut through routine events to the ones with real consequences.

#CertificateManagement #PKI

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

CertKit now supports ACME ARI and 6-day certificates.

ARI means the CA tells us when to renew. We check it multiple times a day. Your next mass revocation event? Just another boring Tuesday.

Nothing to configure.

https://www.certkit.io/blog/acme-ari-and-6-day-certificates #PKI #infosec

ACME ARI support and 6-day certificates
CertKit SSL Certificate Management

ACME ARI support and 6-day certificates

CertKit now polls Let's Encrypt multiple times a day to check when each certificate should renew. That means mass revocations happen automatically, without you doing anything. We also added support for 6-day certificates for environments where 90 days isn't short enough.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

Curious how CertKit works? I made a page for that.

https://www.certkit.io/how-it-works

How CertKit automates SSL certificate lifecycle management
CertKit SSL Certificate Management

How CertKit automates SSL certificate lifecycle management

CertKit automates your entire certificate lifecycle. Issue certificates via ACME, deploy them with the CertKit Agent, and verify everything with real TLS checks. No open ports, no ACME on your servers, no DNS changes.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 2mo ago
Replying to
@ghosttie@mastodon.gamedev.place Two reasons: Required automation. At 90 days, Lets Encrypt always needed you to automate certificates end to end. And that's actually really difficult for most organizations. There's a lot of devices that simply do not support ACME and never will. No support. Lots of IT shops need that safety net, need that number to call when things go wrong. I think the 47-day mandate is going to drive a lot of new folks to Let's Encrypt
0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 7mo ago

CertKit Agent 1.6: RRAS support, deploy windows, and agent locking.

Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized.

https://www.certkit.io/blog/agent-1.6

#CertificateAutomation #WebPKI

CertKit Agent update: RRAS support, deploy windows, and agent locking
CertKit SSL Certificate Management

CertKit Agent update: RRAS support, deploy windows, and agent locking

The CertKit Agent now supports Microsoft RRAS for VPN certificate management. We also added deploy windows so you can control when certificate updates happen, and agent locking to protect your infrastructure even if CertKit itself were ever compromised.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 3mo ago

One SonicWall. The SSL certificate import API is barely documented and shifts between SonicOS versions. Now repeat for every appliance you run, up to 12x a year.

Build it yourself and you maintain it forever.

https://www.certkit.io/blog/automating-sonicwall-certificates

#SSL

Automating SonicWall Certificate Deployment with the SonicOS API
CertKit SSL Certificate Management

Automating SonicWall Certificate Deployment with the SonicOS API

Certificate lifetimes are shrinking to 47 days. Manually updating SSL certificates through the SonicWall Administration UI is no longer an option. We automate the process, but SonicOS doesn't make it easy.

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 3mo ago

Live SSL certificate deployment next week. Not a demo environment. Real setup, discovery through renewal. If something breaks, we fix it.

June 16, 11am Central. With Richard Hicks. Free.

https://us02web.zoom.us/webinar/register/6417812064399/WN_iBrdj5xmT56lUWG1jrf3ZQ

#CertificateManagement #WindowsIT

Video Conferencing, Web Conferencing, Webinars, Screen Sharing
Zoom

Video Conferencing, Web Conferencing, Webinars, Screen Sharing

Zoom is the leader in modern enterprise video communications, with an easy, reliable cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems. Zoom Rooms is the original software-based conference room solution used around the world in board, conference, huddle, and training rooms, as well as executive offices and classrooms. Founded in 2011, Zoom helps businesses and organizations bring their teams together in a frictionless environment to get

0
0
0
0
Open post
CertKit @certkit@infosec.exchange
· 4mo ago

Apple's 398-day limit exempts private CAs. Most people stopped reading there.

There's a second Apple requirement: all TLS certs, 825 days max. Safari silently rejects anything longer. No bypass, no details.

https://www.certkit.io/blog/apple-doesnt-care-who-signed-your-certificate

#PrivatePKI #PKI

Apple doesn't care who signed your certificate
CertKit SSL Certificate Management

Apple doesn't care who signed your certificate

Running a private CA to escape the public cert treadmill makes sense. Apple still enforces an 825-day validity limit in Safari on every TLS certificate, no matter who issued it.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:03:25 UTC