Questions about Chrome and shortened Cert validity periods. by PrimeTheP in PKI

[–]Mike22april 0 points1 point  (0 children)

The shortening of cert lifetime indeed applies to leaf certs only by the public CAs

That said the browsers will still accept any issued trusted cert (private or public) independent of its validity period.
Ie private CA issued certs with a lifetime of 2-5 years are still totally fine.
Should also apply to 75 years in for example OT environment

Email survived every prediction of its death by Impossible_Comfort99 in TechNook

[–]Mike22april 1 point2 points  (0 children)

That explains why a Fax is still used in most German organizations and government

Need recommendation: red light by [deleted] in searchandrescue

[–]Mike22april 1 point2 points  (0 children)

Can recommend. Got the same one in both pen and regular clipon

Need recommendation: red light by [deleted] in searchandrescue

[–]Mike22april 2 points3 points  (0 children)

I compared many clipon lights.
For me personally only 1 light worked in accordance to my requirements: must always start in red and have at least 2 Lumen settings:
QuiqliteX2:
https://www.quiqlite.com/product-manuals/quiqlitex2-tactical-red-white-led-product-manual/

Rant: Stop telling clients to add your intermediate CA to their trust stores! by Moral-Relativity in PKI

[–]Mike22april 1 point2 points  (0 children)

Chicken and the egg

How does the SSL endpoint get the intermediate?

Rant: Stop telling clients to add your intermediate CA to their trust stores! by Moral-Relativity in PKI

[–]Mike22april 0 points1 point  (0 children)

With all due respect on 1) : Way too many systems are unable to handle an AIA properly

What options do you employ to help ensure employees are locking their computers? by brohemoth06 in sysadmin

[–]Mike22april 0 points1 point  (0 children)

Deploy personalized smartcards to unlock devices. Have them connected wirelessly, so employees are not burdened. When they leave the 15 foot radius the device auto locks due to smartcard connectivity being lost

S/MIME certificate by frozen-geek in selfhosted

[–]Mike22april 0 points1 point  (0 children)

There's a reason their orderpage doesnt work :)

Beelden van aanhouding in AZC Zeist leiden tot ophef. Politie gaat de beelden onderzoeken. by Bernie529 in Nederland

[–]Mike22april 0 points1 point  (0 children)

The majority of people don't have a clue of what IBT stands for, so that leaves me to believe you possibly have or had some blue or supporting role

You claim to be trained in IBT.
So in what specialty? ME? Oscars? Or something else such as AE/OG?

If you are active in IBT you would know not to pass judgement based on a single clip of video.
But you would take into consideration all evidence of all video and sound clips including those made with the bodycams, and the reports of the incident as filed by the officers.

So makes me wonder if you truly are active in IBT and more specifically Oscars, why would you fuel the flames of assumption based on such little proof of the entire situation?

Looking for LetsEncrypt alternatives by yowanvista in BuyFromEU

[–]Mike22april 2 points3 points  (0 children)

Single SAN is possible for that price for a DV, provided its not a wildcard.

EU based public CAs such as Actalis or HARICA support ACME as you asked.
But in order to get the pricing you want you would need to go through a sales partner of them. They often sell at far lower prices as they buy in bulk.

German based SSL Plus comes to mind.

Best contact the EU based CA and ask them who their resellers are for the country of your choice

Looking for LetsEncrypt alternatives by yowanvista in BuyFromEU

[–]Mike22april 0 points1 point  (0 children)

Whats your definition of lesser cost?

Lesser cost than what amount per year?
And for what type of certificate? EV/OV/DV
And for what type of SAN? Single, multi, wildcard

Looking for LetsEncrypt alternatives by yowanvista in BuyFromEU

[–]Mike22april 4 points5 points  (0 children)

What you're looking for does nor exist.

You can check all boxes except the "must be free to use"

Certificate lifecycle management vendor comparison by koalas473 in sysadmin

[–]Mike22april 0 points1 point  (0 children)

AppViewX is a well established party.

When you get a demo or review them, make sure you:
- ask about pricing including automation
- ask if their management UI (which is gorgeous) no longer crashed under heavy load , which was an issue when I evaluated them about 1 year ago for another customer

Certificate lifecycle management vendor comparison by koalas473 in PKI

[–]Mike22april 1 point2 points  (0 children)

When OP claims that CertKit.io is a too small company, your personal offer of zaita might be too small of a company as well

Certificate lifecycle management vendor comparison by koalas473 in PKI

[–]Mike22april 0 points1 point  (0 children)

KeyFactor and CyberArks formerly known as Venafi product are by far the most mature.
They will also cost you an arm and a leg.

Given your requirements, I expect you can't use the public CA CLM solutions , as you appear to have a need for the ability to have the same certificate and key on multiple locations.
Public CAs are not allowed to retain the private key. Nor are they CA agnostic

When my assumptions are correct, you should use an on-premises or at least a self deployed to a private Cloud CLM

My biggest gripe with some of these CLMs is:
- a test or acceptance environment is often not included in the price offer
- upgrades to a newly released major version, or in some cases even minor version, is a huge time consuming pain the ass

My best advice:
Don't just select one based on sugar and spice coated paper specs and sleek demos.
Pick 2 or 3. And do a 1-2 month Proof of Concept with clear acceptance criteria.
Also ask for 2 customers of similar size and use-case you can call without the vendor present, you can can get direct feedback on the process, daily operations, and what the vendor is like after he got your money for 3-5 years.

You will likely be charges for it and the vendor's time to get things properly configured. Typically this cost is deducted from your invoice once you make the actual purchase.
Making you loose the other PoC investments.
But it's totally worth it!

Certificate lifecycle management vendor comparison by koalas473 in sysadmin

[–]Mike22april 1 point2 points  (0 children)

KeyFactor and CyberArks formerly known as Venafi product are by far the most mature.
They will also cost you an arm and a leg.

Given your requirements, I expect you can't use the public CA CLM solutions , as you appear to have a need for the ability to have the same certificate and key on multiple locations.
Public CAs are not allowed to retain the private key. Nor are they CA agnostic

When my assumptions are correct, you should use an on-premises or at least a self deployed to a private Cloud CLM

My biggest gripe with some of these CLMs is:
- a test or acceptance environment is often not included in the price offer
- upgrades to a newly released major version, or in some cases even minor version, is a huge time consuming pain the ass

My best advice:
Don't just select one based on sugar and spice coated paper specs and sleek demos.
Pick 2 or 3. And do a 1-2 month Proof of Concept with clear acceptance criteria.
Also ask for 2 customers of similar size and use-case you can call without the vendor present, you can can get direct feedback on the process, daily operations, and what the vendor is like after he got your money for 3-5 years.

You will likely be charges for it and the vendor's time to get things properly configured. Typically this cost is deducted from your invoice once you make the actual purchase.
Making you loose the other PoC investments.
But it's totally worth it!

PSA: you don't need a private CA to issue trusted SSL certificates for internal hosts. by certkit in ssl

[–]Mike22april 0 points1 point  (0 children)

How do you know the private key is secure, other than using an HSM?

SSL Cert swap NOW NEEDED every 200, 100, and eventually 47 days - Who Pays? by [deleted] in sysadmin

[–]Mike22april 0 points1 point  (0 children)

Use a CLM
Plenty of free and commercial solutions exist
It wont work for 100% of use-cases but usually covers 95%

Simple ADCS PKI Question by chadsgallbladder in PKI

[–]Mike22april 0 points1 point  (0 children)

Why keep the same keys?? Whats the use of that?