<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>certsecure.ch</title><description>Tested, practical guides on public key infrastructure — certificates, CAs, TLS and the standards that hold them together.</description><link>https://certsecure.ch/</link><language>en</language><atom:link href="https://certsecure.ch/rss.xml" rel="self" type="application/rss+xml"/><item><title>Advisory: Chain Validation Bypass in Common TLS Stacks</title><link>https://certsecure.ch/guides/cve/</link><guid isPermaLink="true">https://certsecure.ch/guides/cve/</guid><description>A name-constraint parsing flaw lets a crafted intermediate assert authority it was never granted. Affected versions and fixes inside.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>Advisories</category><category>Advisories</category><category>TLS/SSL</category><category>Vulnerability</category></item><item><title>Certificate Revocation: CRL vs OCSP vs Stapling</title><link>https://certsecure.ch/guides/revocation/</link><guid isPermaLink="true">https://certsecure.ch/guides/revocation/</guid><description>Revocation is where most PKI deployments quietly fall apart. Here is how each mechanism works and which one to actually rely on.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Key Management</category><category>Key Management</category><category>Revocation</category><category>OCSP</category><category>TLS/SSL</category></item><item><title>How X.509 Certificates Actually Work</title><link>https://certsecure.ch/guides/x509/</link><guid isPermaLink="true">https://certsecure.ch/guides/x509/</guid><description>A field guide to the certificate you stare at every day: fields, extensions, the chain, and what a validator is really checking.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>PKI Basics</category><category>PKI Basics</category><category>X.509</category><category>Certificates</category></item><item><title>Building a Two-Tier CA Hierarchy with OpenSSL</title><link>https://certsecure.ch/guides/twotier/</link><guid isPermaLink="true">https://certsecure.ch/guides/twotier/</guid><description>Stand up an offline root and an issuing intermediate from scratch, with sane extensions, CRL and OCSP endpoints wired in.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Tutorials</category><category>Tutorials</category><category>Certificate Authority</category><category>OpenSSL</category></item><item><title>ACME and Fully Automated Certificate Management</title><link>https://certsecure.ch/guides/acme/</link><guid isPermaLink="true">https://certsecure.ch/guides/acme/</guid><description>How the ACME protocol issues, renews and revokes certificates without a human in the loop, and where automation still bites.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>Tutorials</category><category>Tutorials</category><category>ACME</category><category>Automation</category></item><item><title>Post-Quantum Cryptography: Preparing Your PKI</title><link>https://certsecure.ch/guides/pqc/</link><guid isPermaLink="true">https://certsecure.ch/guides/pqc/</guid><description>Hybrid certificates, crypto-agility and the migration timeline. What to inventory now before the standards land in production.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>Standards</category><category>Standards</category><category>Post-Quantum</category><category>Migration</category></item><item><title>Certificate Transparency Logs, Explained</title><link>https://certsecure.ch/guides/ct/</link><guid isPermaLink="true">https://certsecure.ch/guides/ct/</guid><description>What SCTs are, why browsers demand them, and how CT turns misissuance from a secret into a public, auditable record.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Standards</category><category>Standards</category><category>Certificate Transparency</category><category>Auditing</category></item><item><title>Choosing Key Sizes and Algorithms in 2026</title><link>https://certsecure.ch/guides/keysize/</link><guid isPermaLink="true">https://certsecure.ch/guides/keysize/</guid><description>RSA-3072, ECDSA P-256 or Ed25519? A practical decision guide for what to deploy today and what to avoid.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>Key Management</category><category>Key Management</category><category>Algorithms</category><category>Best Practices</category></item></channel></rss>