Live data from Hacker News

Viewing profile — toddgardner

toddgardner

HN member
Joined
Tue, Dec 10, 2013, 4:42 PM UTC
HN karma
359
Public activity
66 items

About toddgardner

I start things.

Recent public activity

  1. comment
    Comment #48542743

    OP Here. What you fail to grasp is that there are multiple sizes of IT organizations on this planet. The vast majority of them have less than 10 total admins. For them, they could …

  2. comment
  3. story
  4. story
  5. comment
    Comment #47618945

    Nice rewrite. The SAN support is the right call, a lot of older generators trip on that. One thing worth knowing if you're using this for internal services: generating the cert is …

  6. comment
    Comment #47579562

    I am talking to so many mid-sized IT shops that still have lots of legacy on-prem windows systems or specialty software where Certbot or ACME renewals is hard. This sort of thing g…

  7. comment
    Comment #47144257

    If you never want this to happen again to your systems, we’re building a tool that bakes monitoring and validation into automatic cert renewals. https://www.certkit.io/ >

  8. comment
    Comment #46290672

    > What is the problem with stale certificates if a domain changes hands? The previous owners have valid certificates for up to 398 days. If they are a malicious party cable of doin…

  9. comment
    Comment #46282755

    For all the folks worried about how hard automation is going to be, this is what my team and I have been working on for the past year: https://www.certkit.io/certificate-management…

  10. comment
    Comment #46282683

    It's not really a stupid problem, its the BygoneSSL problem: https://www.certkit.io/blog/bygonessl-and-the-certificate-th...

  11. comment
    Comment #46282669

    Man, I agree. The whole thing sucks so much. We started building a centralized way to do this internally last year to get better visibility into renewals and expirations: We're doi…

  12. comment
    Comment #46282653

    It's more complicated than that. Apple (along with Google and Mozilla) basically held the CA's hostage. They started unilaterally reducing lifetimes. It was happening whether the C…

  13. comment
    Comment #46277169

    If you want to learn more about Certificate Transparency Logs, how to pull and search them, we just did a 3 part series about how we did this at CertKit: https://www.certkit.io/blo…

  14. story
  15. comment
    Comment #45986338

    Does anyone read articles before commenting? lol

  16. comment
    Comment #45986335

    Yea totally. this is a balance. Very few times should you manage the actual hardware yourself. But often a cloud is overly complex for what you need. 10 years ago we left MS Azure …

  17. comment
    Comment #45986223

    I tend to sell to a wide variety of customers. They tend not to give a crap if a cloud provider is down, its still our problem to make it right.

  18. comment
    Comment #45983782

    Yea agreed. I don't build my own CDNs. But I don't choose cloudflare either, because its too complicated and I don't need that. So I choose the simplest possible thing with as litt…

  19. comment
    Comment #45982069

    wow, yea. that's foolish. Fixing.

  20. comment
    Comment #45981806

    How you approach this is very different depending on the size of organization. We're a small shop (3), but we deliver big services to lots of people. We do this by owning everythin…

  21. comment
    Comment #45981780

    An alternative to multiple providers is to use commoditized providers. By using simple infrastructure rather than cloud platforms, I can redploy my infrastructure using ansible wit…

  22. story
  23. comment
    Comment #45492214

    For twenty years, Certificate Authorities ran the perfect protection racket. Then SHA-1 got shattered, Apple went rogue, and certificates went from lasting 3 years to 47 days. This…

  24. story
  25. story