{"id":28381,"date":"2020-03-12T16:30:05","date_gmt":"2020-03-12T20:30:05","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=28381"},"modified":"2020-03-12T16:53:10","modified_gmt":"2020-03-12T20:53:10","slug":"tls-increasingly-exists-in-three-different-worlds","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2020\/03\/12\/tls-increasingly-exists-in-three-different-worlds\/","title":{"rendered":"TLS Increasingly Exists in Three Different Worlds"},"content":{"rendered":"<p><a href=\"https:\/\/utcc.utoronto.ca\/~cks\/space\/blog\/tech\/TLSThreeWorlds\">Chris Siebenmann<\/a>:<\/p>\n<blockquote cite=\"https:\/\/utcc.utoronto.ca\/~cks\/space\/blog\/tech\/TLSThreeWorlds\">\n<p>The first world is <em>web TLS<\/em>, which is dominated by browsers. This\nis the familiar world of public HTTPS, with public Certificate\nAuthorities, requirements for certificate transparency, and so on.\nThe browsers increasingly are calling the shots here and they&rsquo;re\npushing for things like short certificate lifetimes, aggressively\nmoving away from old TLS versions, and so on.<\/p>\n<p>[&#8230;]<\/p>\n<p>The second is <em>non-web public TLS<\/em>, where TLS is used for protocols\nlike IMAP, SMTP (with STARTTLS), and so on. This world still uses\npublic CAs, but it has a lot more old clients and servers and is a\nlot slower to deprecate old TLS and SSL versions, move to shorter\ncertificate lifetimes, and so on.<\/p>\n<p>[&#8230;]<\/p>\n<p>The third world is <em>internal TLS<\/em>, where TLS is used inside an\norganization or a service to encrypt connections and often to\nauthenticate them (and sometimes it&rsquo;s used between organizations).<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/02\/24\/safari-to-reject-https-certificates-longer-than-a-year\/\">Safari to Reject HTTPS Certificates Longer Than a Year<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Chris Siebenmann: The first world is web TLS, which is dominated by browsers. This is the familiar world of public HTTPS, with public Certificate Authorities, requirements for certificate transparency, and so on. The browsers increasingly are calling the shots here and they&rsquo;re pushing for things like short certificate lifetimes, aggressively moving away from old TLS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2020-03-12T20:30:29Z","apple_news_api_id":"83ba7748-2e4b-4d3b-b15e-42d94d5f327f","apple_news_api_modified_at":"2020-03-12T20:53:13Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/Ag7p3SC5LTTuxXkLZTV8yfw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[150,424,48,481,581,96],"class_list":["post-28381","post","type-post","status-publish","format-standard","hentry","category-technology","tag-email","tag-imap","tag-security","tag-smtp","tag-ssltls","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/28381","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=28381"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/28381\/revisions"}],"predecessor-version":[{"id":28385,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/28381\/revisions\/28385"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=28381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=28381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=28381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}