Kategori
Sertifikalar ve PKI
Bu kategorideki tüm araçlar ve makaleler, tek bir yerde toplandı.
Araçlar
ACME dns-01 TXT computer
Compute the TXT record for an ACME dns-01 challenge, from the token and account key.
CSR kod çözücü
Bir PKCS#10 sertifika imzalama isteğini kod çözerek konusunu, açık anahtarını, istenen SAN'ları ve uzantıları ve özniteliklerini okuyun; tümü tarayıcınızda.
Let's Encrypt rate-limit planner
Plan certificate issuance for a set of hostnames: group them by registered domain and see how they map onto Let's Encrypt's rate limits.
Sertifika yenileme planlayıcısı
Bir TLS sertifikasının geçerliliğini, CA/Browser Forum'un 47 günlük takvimine uyup uymadığını ve bunun gerektirdiği yenileme sıklığını hesaplayın; tümü çevrimdışı.
X.509 Sertifika Çözücü
Konusunu, verenini, geçerlilik penceresini, açık anahtarını ve v3 uzantılarını SHA-256 ve SHA-1 parmak izleriyle okumak için PEM, base64 veya hex bir sertifika yapıştır. Tamamen tarayıcında çalışır.
Makaleler
Bir X.509 sertifikasının anatomisi
Bir TLS sertifikasının içinde ne yaşadığı, ASN.1/DER baytlarının nasıl yapılandırıldığı, v3 uzantılarının aslında neyi denetlediği ve bir sertifikayı kod çözmenin ona güvenmekle aynı şey olmadığı.
OkuPEM, DER ve sertifika dosya biçimleri
Aynı sertifikanın neden bu kadar çok dosya biçiminde geldiği, PEM ve DER'in aslında ne olduğu ve .crt, .pem, .pfx ile .p12'nin gerçekte ne tuttuğu.
OkuSertifika imzalama istekleri ve sertifikaların nasıl verildiği
Bir CSR'nin ne içerdiği, özel anahtarınızın neden asla makinenizden ayrılmadığı, bir CA'nın nasıl doğruladığı ve verdiği, ve ACME'nin tüm alışverişi nasıl otomatikleştirdiği.
OkuSertifika doğrulaması aslında nasıl çalışır
Bir istemcinin bir sertifikanın güvenilir olduğuna karar vermek için çalıştırdığı adımlar: zinciri kurmak, imzaları ve tarihleri denetlemek, adı eşleştirmek ve kısıtlamaları uygulamak.
OkuSertifika iptali: CRL, OCSP ve kısa ömürlü sertifikalar
Bir sertifikanın bazen süresi dolmadan iptal edilmesi gerektiği, klasik iptal sistemlerinin neden zayıf çalıştığı ve sektörün bunun yerine neden sertifika ömürlerini küçülttüğü.
OkuAuthority Information Access: The OCSP and CA Issuers URLs
The AIA extension carries two kinds of pointer: where to ask whether a certificate is revoked (OCSP) and where to fetch the issuer's own certificate (CA Issuers). What each is for, why they are easy to confuse, and what the inspector shows.
OkuOCSP Must-Staple: Closing the Soft-Fail Gap
Real-time OCSP checking has a fatal weakness: when the responder is unreachable, clients usually proceed anyway. OCSP stapling and the Must-Staple flag are the fix. What the TLS Feature extension declares, and the operational risk it carries.
OkuACME: how certificates issue and renew themselves
How the ACME protocol automates certificate issuance end to end: the account, the order, the three challenge types, the dns-01 record you publish, and the finalize-and-download step that produces the certificate.
OkuThe 47-day era: how TLS certificate lifetimes are shrinking
The CA/Browser Forum's SC-081v3 schedule takes maximum public TLS validity from 398 days down to 47 by 2029, in three steps. What the phases are, why 47, and what it does to renewal volume.
OkuCertificate validity windows: notBefore, notAfter, and renewal lead time
How a certificate's lifetime is defined by two timestamps, how that length is measured against the cap, why validity is not the same as time remaining, and how to choose a renewal lead time.
OkuLet's Encrypt: the free CA and its rate limits
What Let's Encrypt is, why its certificates are short-lived, and how its rate limits actually work: the per-registered-domain and per-account limits, the exact-set and authorization-failure limits, and why ARI renewals are exempt from all of them.
OkuDCV and SII reuse: the validation cadence behind the renewal cadence
Issuing a certificate means proving domain control and, for OV/EV, organization identity. SC-081v3 shrinks how long those proofs can be reused — DCV to 10 days by 2029 — which reshapes renewal as much as validity does.
OkuRenewing before expiry: lead time, ACME, and ARI
Why late renewal causes outages, how ACME automates issuance and renewal, how the ARI extension lets a CA steer the renewal window, and how to pick a lead time that leaves room to retry.
OkuPublic vs private PKI: which certificates SC-081v3 governs
The 47-day schedule binds publicly trusted TLS certificates only. What separates public from private PKI, why internal CAs are exempt, and how to read the planner's compliance verdict for an internal certificate.
Oku