Tag
Explains how to set up TLS certificates for internal services using split-horizon DNS, a VPN with DNS resolver, and ACME clients like acme.sh with Let's Encrypt, providing a practical alternative to self-signed certificates.
An analysis and reproduction of lawful TLS wiretapping using ACME automation, based on a real incident involving Russian XMPP service Jabber.ru, demonstrating how certificate-based intercepts can be implemented and detected.
The CA/Browser Forum has voted to make ACME CAA extensions mandatory by March 2027, a key step toward strong cryptographic domain validation using DNSSEC.