I’m surprised by the number of requests to port 80, especially for requests to PKI certificate related domains. I assume there’s an element of chicken-and-egg somewhere that means they can’t use TLS in certain cases. Can anyone offer insight into why this is OK and not subject to MITM attacks on the certificate validation/supply chain?
It may sound “insecure”, but if you can’t trust X509 without HTTPS, you effectively can’t trust either X509 or HTTPS.
This is why we have layers in software. We trust X509 because of fundamental math. Therefore we trust HTTPS built on X509. Therefore we trust systems built on HTTPS.
Everything is perfectly fine.