HNHacker News
TopNewBestAskShowJobs

throwaway96751

7 karma · joined April 15, 2025

submissionscomments
throwaway96751··on TLS certificate lifetimes will officially reduce to 47 days
> SSL is one of those weird niche subjects that no one learns until they run into a problem

Yep, that me.

Thanks for the blog post!

throwaway96751··on TLS certificate lifetimes will officially reduce to 47 days
I think this method works best when you can verify the answer. So it has to be either a specific type of question (a request to generate code, which you can then run and test), or you have to know enough about the subject to be able to spot mistakes.
throwaway96751··on TLS certificate lifetimes will officially reduce to 47 days
Thanks, looks exactly like what I wanted
throwaway96751··on TLS certificate lifetimes will officially reduce to 47 days
Off-topic: What is a good learning resource about TLS?

I've read the basics on Cloudflare's blog and MDN. But at my job, I encountered a need to upload a Let's encrypt public cert to the client's trusted store. Then I had to choose between Let's encrypt's root and intermediate certs, between key types RSA and ECDSA. I made it work, but it would be good to have an idea of what I'm doing. For example why root RSA key worked even though my server uses ECDSA cert. Before I added the root cert to a trusted store, clients used to add fullchain.pem from the server and it worked too — why?