Live data from Hacker News

Viewing profile — sudoyear123

sudoyear123

HN member
Joined
Fri, Jan 27, 2017, 10:05 PM UTC
HN karma
106
Public activity
16 items

About sudoyear123

No profile information was provided.

Recent public activity

  1. comment
    Comment #21422373

    This is a very good question. We actually did consider proxy certs and name constraints certs first and had a long discussion at the IETF about these different options. At the end …

  2. comment
    Comment #21421039

    As a CA you can issue certificates for other domains as well which might be undesirable. There are existing mechanisms such as Name constrained CAs and proxy certificates to reduce…

  3. comment
    Comment #21420860

    generalized asn1 parsing can be super tricky and the industry is generally avoiding asn1 for new protocols. There has been some really interesting work from microsoft on verified p…

  4. comment
    Comment #21420391

    DER encoded ASN.1 is used for the X.509 end-entity certificate, however generally this follows how CertificateVerify works in TLS 1.3 https://tools.ietf.org/html/rfc8446#section-4.…

  5. story
  6. story
  7. story
  8. story
  9. story
  10. comment
    Comment #20043894

    This would make a great comparison. I'm not certain whether or not K8's mutual auth supports session ticket resumptions and distribution of short lived ticket keys. The ticket rota…

  11. comment
    Comment #20041064

    Ya they're similar in that they are all signed blobs of data, but different in the sense that they are specifically designed to send authentication information via several layers o…

  12. comment
    Comment #20040587

    There are several access control mechanisms. One such ACL as mentioned in the post is identity certificates which are used to perform access control. Other mechanisms for identity …

  13. story
  14. story
  15. story
  16. story