πŸ” PKI Related Posts

  • Apple Pay and TLS Decryption

    Apple Pay and TLS Decryption

    The process of troubleshooting Apple Pay with TLS decryption can be frustrating due to a lack of useful error messages. This post describes the steps involved to troubleshoot and identifies what hostname needs to be excluded from TLS decryption. Read more

  • OpenBB Terminal and Decryption

    OpenBB Terminal and Decryption

    In my experience with OpenBB Terminal on macOS, I encountered SSL Certificate verify issues, likely due to corporate SSL/TLS decryption. I found a solution by appending my certificates in base64 PEM format to the /Applications/OpenBB Terminal/.OpenBB/certifi/cacert.pem file, effectively resolving the errors. However, after each software upgrade, this process must be repeated. Read more

  • Homebrew and Decryption

    Homebrew and Decryption

    A detailed solution for getting Homebrew to work on devices performing SSL decryption. It outlines steps to resolve SSL certificate errors by configuring curl with a custom certificate authority, ensuring seamless Homebrew updates and installations on macOS. Read more

  • Crowdsourcing Pinned Certificate Information

    Crowdsourcing Pinned Certificate Information

    Understanding the complexities of pinned certificates doesn’t need to be hard. By crowdsourcing the collective knowledge of what we find, it can be easier to implement a decryption policy. Read more

  • Questing for a Decryption Policy

    Questing for a Decryption Policy

    In my home lab experiments with TLS decryption policies, I discovered unique challenges with mobile apps having Pinned Certificates, impacting functionality. This post outlines a phased approach to implement decryption, balancing security with operational needs, starting with a ‘No Decrypt’ and expanding from there. Read more

  • RFC 5280 – What?! What alien language do you speak of?

    RFC 5280 – What?! What alien language do you speak of?

    πŸš€ Embark on a Cryptographic Journey with RFC 5280! Greetings to all digital wanderers and crypto-enthusiasts! 🌐 Today, we unravel the mystical realm of digital certificates and embark on a fascinating journey to decrypt the process of certificate evaluation, all through the lens of the famed RFC 5280! πŸ“œβœ¨ First things first: What’s a digital Read more