TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A Note from Our Executive Director

31 点作者 soheilpro5 个月前

4 条评论

politelemon5 个月前
Key bit:<p>&gt; but we are going to introduce a new offering that’s a big shift from anything we’ve done before - short-lived certificates. Specifically, certificates with a lifetime of six days. This is a big upgrade for the security of the TLS ecosystem because it minimizes exposure time during a key compromise event.
samgranieri5 个月前
On a side note, I&#x27;ve had fun playing with something like this with Caddy and StepCA and bind running in a homelab. I&#x27;ve managed to, using the rfc2136 plugin, managed to rotate certs every ten minutes.<p>Every six days is fine, just use something like Caddy that rotates the certs for you and it should just be set it and forget it.<p>Yes, I realize this is a bit glib.
评论 #42402289 未加载
rurban5 个月前
Prossimo: That would be rustls, a project that bypassed openssl in every aspect by now. Really everybody should switch over.<p><a href="https:&#x2F;&#x2F;www.memorysafety.org&#x2F;initiative&#x2F;rustls&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.memorysafety.org&#x2F;initiative&#x2F;rustls&#x2F;</a>
nodesocket5 个月前
Interesting choice of 6 days. Any reason 6 was picked?
评论 #42401937 未加载
评论 #42401345 未加载