Viewing profile — toddgardner
toddgardner
HN member- Joined
- Tue, Dec 10, 2013, 4:42 PM UTC
- HN karma
- 359
- Public activity
- 66 items
- HN profile
- View on Hacker News ↗
About toddgardner
Recent public activity
-
comment
Comment #48542743
OP Here. What you fail to grasp is that there are multiple sizes of IT organizations on this planet. The vast majority of them have less than 10 total admins. For them, they could …
- comment
- story
- story
-
comment
Comment #47618945
Nice rewrite. The SAN support is the right call, a lot of older generators trip on that. One thing worth knowing if you're using this for internal services: generating the cert is …
-
comment
Comment #47579562
I am talking to so many mid-sized IT shops that still have lots of legacy on-prem windows systems or specialty software where Certbot or ACME renewals is hard. This sort of thing g…
-
comment
Comment #47144257
If you never want this to happen again to your systems, we’re building a tool that bakes monitoring and validation into automatic cert renewals. https://www.certkit.io/ >
-
comment
Comment #46290672
> What is the problem with stale certificates if a domain changes hands? The previous owners have valid certificates for up to 398 days. If they are a malicious party cable of doin…
-
comment
Comment #46282755
For all the folks worried about how hard automation is going to be, this is what my team and I have been working on for the past year: https://www.certkit.io/certificate-management…
-
comment
Comment #46282683
It's not really a stupid problem, its the BygoneSSL problem: https://www.certkit.io/blog/bygonessl-and-the-certificate-th...
-
comment
Comment #46282669
Man, I agree. The whole thing sucks so much. We started building a centralized way to do this internally last year to get better visibility into renewals and expirations: We're doi…
-
comment
Comment #46282653
It's more complicated than that. Apple (along with Google and Mozilla) basically held the CA's hostage. They started unilaterally reducing lifetimes. It was happening whether the C…
-
comment
Comment #46277169
If you want to learn more about Certificate Transparency Logs, how to pull and search them, we just did a 3 part series about how we did this at CertKit: https://www.certkit.io/blo…
- story
-
comment
Comment #45986338
Does anyone read articles before commenting? lol
-
comment
Comment #45986335
Yea totally. this is a balance. Very few times should you manage the actual hardware yourself. But often a cloud is overly complex for what you need. 10 years ago we left MS Azure …
-
comment
Comment #45986223
I tend to sell to a wide variety of customers. They tend not to give a crap if a cloud provider is down, its still our problem to make it right.
-
comment
Comment #45983782
Yea agreed. I don't build my own CDNs. But I don't choose cloudflare either, because its too complicated and I don't need that. So I choose the simplest possible thing with as litt…
-
comment
Comment #45982069
wow, yea. that's foolish. Fixing.
-
comment
Comment #45981806
How you approach this is very different depending on the size of organization. We're a small shop (3), but we deliver big services to lots of people. We do this by owning everythin…
-
comment
Comment #45981780
An alternative to multiple providers is to use commoditized providers. By using simple infrastructure rather than cloud platforms, I can redploy my infrastructure using ansible wit…
- story
-
comment
Comment #45492214
For twenty years, Certificate Authorities ran the perfect protection racket. Then SHA-1 got shattered, Apple went rogue, and certificates went from lasting 3 years to 47 days. This…
- story
- story