Certificates gone bad | The Backend Engineering Show

The Backend Engineering Show with Hussein Nasser

Episode | Podcast

Date: Fri, 08 Oct 2021 02:15:07 GMT

<p>Certificates contain useful metadata including the public key, domain name, signature, etc. However, the private key can be leaked which causes the certificate to be invalid/dangerous to keep around. In that particular situation, we need a mechanism to revoke certificates and that is what I’m going to discuss in this show.</p> <p><br /></p> <p>0:00 Intro</p> <p>0:30 Why Certificates</p> <p>12:00 Certificates can go bad</p> <p>14:50 Certificate Revocation Lists (CRLs)</p> <p>18:30 OCSP (Online Certificate Status Protocol)</p> <p>20:40 OCSP Stapling</p> <p>24:30 Best certificates are short</p> <p>26:30 Summary</p> <p>Become a Member on YouTube</p> <p>https://www.youtube.com/channel/UC_ML5xP23TOWKUcc-oAE_Eg/join</p> <p>🔥 Members Only Content</p> <p>https://www.youtube.com/playlist?list=UUMO_ML5xP23TOWKUcc-oAE_Eg</p> <p>Support my work on PayPal</p> <p>https://bit.ly/33ENps4</p>