Viewing profile — sudoyear123
sudoyear123
HN member- Joined
- Fri, Jan 27, 2017, 10:05 PM UTC
- HN karma
- 106
- Public activity
- 16 items
- HN profile
- View on Hacker News ↗
About sudoyear123
No profile information was provided.
Recent public activity
-
comment
Comment #21422373
This is a very good question. We actually did consider proxy certs and name constraints certs first and had a long discussion at the IETF about these different options. At the end …
-
comment
Comment #21421039
As a CA you can issue certificates for other domains as well which might be undesirable. There are existing mechanisms such as Name constrained CAs and proxy certificates to reduce…
-
comment
Comment #21420860
generalized asn1 parsing can be super tricky and the industry is generally avoiding asn1 for new protocols. There has been some really interesting work from microsoft on verified p…
-
comment
Comment #21420391
DER encoded ASN.1 is used for the X.509 end-entity certificate, however generally this follows how CertificateVerify works in TLS 1.3 https://tools.ietf.org/html/rfc8446#section-4.…
- story
- story
- story
- story
- story
-
comment
Comment #20043894
This would make a great comparison. I'm not certain whether or not K8's mutual auth supports session ticket resumptions and distribution of short lived ticket keys. The ticket rota…
-
comment
Comment #20041064
Ya they're similar in that they are all signed blobs of data, but different in the sense that they are specifically designed to send authentication information via several layers o…
-
comment
Comment #20040587
There are several access control mechanisms. One such ACL as mentioned in the post is identity certificates which are used to perform access control. Other mechanisms for identity …
- story
- story
- story
- story