Kategorya
Mga certificate at PKI
Lahat ng kagamitan at artikulo sa kategoryang ito, tinipon sa isang lugar.
Mga Kagamitan
ACME dns-01 TXT computer
Compute the TXT record for an ACME dns-01 challenge, from the token and account key.
CSR decoder
I-decode ang isang PKCS#10 certificate signing request upang basahin ang subject, public key, hiniling na mga SAN at extension, at mga attribute nito; lahat ay sa iyong browser.
Let's Encrypt rate-limit planner
Plan certificate issuance for a set of hostnames: group them by registered domain and see how they map onto Let's Encrypt's rate limits.
Tagaplano ng pag-renew ng sertipiko
Tukuyin ang bisa ng isang TLS certificate, kung umaangkop ito sa 47-araw na iskedyul ng CA/Browser Forum, at ang dalas ng pag-renew na kaakibat nito; lahat ay offline.
X.509 Certificate Decoder
Mag-paste ng PEM, base64, o hex na certificate upang basahin ang subject, issuer, validity window, public key, at mga v3 extension nito, kasama ang SHA-256 at SHA-1 na mga fingerprint. Tumatakbo nang buo sa iyong browser.
Mga Artikulo
Anatomiya ng isang X.509 Certificate
Kung ano ang nabubuhay sa loob ng isang TLS certificate, kung paano nakaayos ang mga ASN.1/DER byte, kung ano talaga ang kinokontrol ng mga v3 extension, at kung bakit ang pag-decode ng isang certificate ay hindi pareho sa pagtitiwala rito.
BasahinPEM, DER, at ang mga certificate file format
Kung bakit ang parehong certificate ay dumarating sa napakaraming hugis ng file, kung ano talaga ang PEM at DER, at kung ano talaga ang hawak ng .crt, .pem, .pfx, at .p12.
BasahinMga certificate signing request at kung paano inisyu ang mga certificate
Kung ano ang nilalaman ng isang CSR, kung bakit hindi kailanman umaalis ang iyong private key sa iyong makina, kung paano nagva-validate at nag-iisyu ang isang CA, at kung paano ina-automate ng ACME ang buong palitan.
BasahinKung paano talaga gumagana ang certificate validation
Ang mga hakbang na pinapatakbo ng isang client upang magpasya na mapagkakatiwalaan ang isang certificate: pagbuo ng chain, pagsuri ng mga lagda at petsa, pagtutugma ng pangalan, at pagpapatupad ng mga constraint.
BasahinCertificate revocation: CRL, OCSP, at mga short-lived na certificate
Kung bakit minsan kailangang kanselahin ang isang certificate bago ito mag-expire, kung bakit mahina ang gana ng mga klasikong sistema ng revocation, at kung bakit sa halip ay pinapaliit ng industriya ang mga lifetime ng certificate.
BasahinAuthority Information Access: The OCSP and CA Issuers URLs
The AIA extension carries two kinds of pointer: where to ask whether a certificate is revoked (OCSP) and where to fetch the issuer's own certificate (CA Issuers). What each is for, why they are easy to confuse, and what the inspector shows.
BasahinOCSP Must-Staple: Closing the Soft-Fail Gap
Real-time OCSP checking has a fatal weakness: when the responder is unreachable, clients usually proceed anyway. OCSP stapling and the Must-Staple flag are the fix. What the TLS Feature extension declares, and the operational risk it carries.
BasahinACME: how certificates issue and renew themselves
How the ACME protocol automates certificate issuance end to end: the account, the order, the three challenge types, the dns-01 record you publish, and the finalize-and-download step that produces the certificate.
BasahinThe 47-day era: how TLS certificate lifetimes are shrinking
The CA/Browser Forum's SC-081v3 schedule takes maximum public TLS validity from 398 days down to 47 by 2029, in three steps. What the phases are, why 47, and what it does to renewal volume.
BasahinCertificate validity windows: notBefore, notAfter, and renewal lead time
How a certificate's lifetime is defined by two timestamps, how that length is measured against the cap, why validity is not the same as time remaining, and how to choose a renewal lead time.
BasahinLet's Encrypt: the free CA and its rate limits
What Let's Encrypt is, why its certificates are short-lived, and how its rate limits actually work: the per-registered-domain and per-account limits, the exact-set and authorization-failure limits, and why ARI renewals are exempt from all of them.
BasahinDCV and SII reuse: the validation cadence behind the renewal cadence
Issuing a certificate means proving domain control and, for OV/EV, organization identity. SC-081v3 shrinks how long those proofs can be reused — DCV to 10 days by 2029 — which reshapes renewal as much as validity does.
BasahinRenewing before expiry: lead time, ACME, and ARI
Why late renewal causes outages, how ACME automates issuance and renewal, how the ARI extension lets a CA steer the renewal window, and how to pick a lead time that leaves room to retry.
BasahinPublic vs private PKI: which certificates SC-081v3 governs
The 47-day schedule binds publicly trusted TLS certificates only. What separates public from private PKI, why internal CAs are exempt, and how to read the planner's compliance verdict for an internal certificate.
Basahin