Advertisement · 728 × 90

Posts by Todd H. Gardner

Preview
CertKit is Out of Beta Why I built a certificate management platform, what's wrong with the way we handle certs today, and why CertKit exists as a commercial product now.

CertKit is out of beta today. After a year, 600+ beta users, and more Windows edge cases than I care to admit, it's a real product.

www.toddhgardner.com/blog/certkit...

4 days ago 1 0 0 0
Preview
CertKit SSL Certificate Lifecycle Management SSL Certificate Lifecycle Management from CertKit handles the certificate tedium. Issue certificates in one click. Automatically deploy them to Linux, Windows, and vendor appliances. Monitor everythin...

The sidecar pattern works but it's still one renewal process per container, which is the problem you're trying to get away from. A central system that pushes certs to pods is cleaner, and gets more important as lifetimes shrink. (I build certkit.io which does this)

1 week ago 1 0 0 0

That quote nails it. cert-manager solves issuance really well but you still end up with no fleet-level view of what's expiring across namespaces. You find out when TLS starts failing, not before.

You end up needing some other system to manage that, like @certkit.io

1 week ago 0 1 0 0

The Windows Certificate Store integration in Agent 1.8 is going to eliminate a lot of the wrapper scripts I see.

www.certkit.io/blog/agent-1.8

1 week ago 2 0 0 0

Let's Encrypt quietly ran a mass revocation drill last week. 3 million real certificates. Most automation never noticed. That's the problem.

1 week ago 0 0 0 0

For the orgs that asked: yes, you can now use CertKit without sending us your private keys. The keystore runs on your infrastructure. Keys never leave.

2 weeks ago 0 0 0 0

The forums answer for deploying certs to multiple servers is always "just write a script." That script quietly becomes the most critical unmonitored piece of infrastructure you own.

2 weeks ago 0 0 0 0
Advertisement

ARI is the protocol that makes mass revocation survivable. Most ACME clients aren’t using it right. Cron jobs don’t cut it when the CA needs a response in 6 hours.

3 weeks ago 0 1 0 0

We added ARI so when a CA has to pull 83,000 certs overnight (hi DigiCert), it's just a quiet Tuesday. Certificate emergencies are getting boring.

1 month ago 0 0 0 0

Renewed doesn't mean deployed. Certificate automation has a verification gap that almost nobody closes, and the consequences are getting worse as cert lifetimes shrink.

1 month ago 0 0 0 0

Certificate expiration is a team problem that keeps getting assigned to one person. We just shipped the tools to fix that.

1 month ago 2 0 0 0
Post image

GitHub felt more reliable when it was a pile of ruby on rails and a fistful of dreams.

1 month ago 3 0 0 0

Get your last 1 year SSL certificates now, while the gettin is good.

1 month ago 1 0 0 0

New post. AI code looks great in the diff and breaks on the first edge case. The instinct is to reverse-engineer the author's assumptions, but that approach is slow and usually wrong.

1 month ago 2 0 2 0

If you’re still treating cert renewals like a calendar reminder, March is gonna be spicy.

1 month ago 0 0 0 0
Kash Patel is presented with the Gold Medal by Kristi Noemish person, he proceeds to pose with the medal, celebrate and pour champagne as hte actual medalists look on.

Kash Patel is presented with the Gold Medal by Kristi Noemish person, he proceeds to pose with the medal, celebrate and pour champagne as hte actual medalists look on.

1 month ago 343 86 2 4
Advertisement

This is one of my favorite cybersecurity posts we've done. I dug into the data on MITM attacks and the threat model most of us worry about is basically fiction.

1 month ago 2 0 0 0

The ICE surge in Minnesota cost $280M, to detain 4k people of whom only 30 were accused of violent crimes.

$9 million per capture of the "worst of the worst". Plus two citizens murdered.

~ Veterans for Peace

1 month ago 4630 2095 123 86

I keep seeing AI-generated diffs that are plausible and wrong in the most annoying ways: missing guards, cargo-cult hooks, swallowed promises.

If your review is vibes, you’re gambling. Production has receipts.

1 month ago 0 0 0 0

Sorry to hear that. Tough times, but you’ll get through it.

1 month ago 0 0 1 0

My first published software was part of a level pack for Duke Nukem.

1 month ago 1 0 0 0

We wanted to understand how rugged English-Scots-Irish culture has shaped America. So we talked to three white South African billionaires at a sex party in the Bahamas.

1 month ago 2617 520 30 14

BygoneSSL isn't theoretical. We found a valid certificate on our own domain, issued to someone we've never met. Getting it revoked was an experience.

1 month ago 1 0 0 0

“Go to sleep with itchy butt, wake up with stinky finger”

This game was such a gem for teenage todd 🤣

1 month ago 1 0 0 0

It’s weird to see people who aren’t from Minnesota talking about Minnesota.

1 month ago 1 0 0 0
Advertisement

We also have amazing Somali and Hmong populations.

The best part of this country is the melding pot of culture.

If he wants English-Scott-Irish, then he should move to England, Scotland, or Ireland.

1 month ago 1 0 0 0
Preview
Jikipedia turns Epstein’s emails into an encyclopedia of the his powerful friends AI-generated dossiers from the Jmail team.

Jikipedia turns Epstein’s emails into an encyclopedia of the his powerful friends

1 month ago 192 64 6 9
Preview
a group of men wearing red white and blue lightning bolt pants ALT: a group of men wearing red white and blue lightning bolt pants

You may not like it, but this is what peak performance looks like.

1 month ago 0 0 0 0
Video

📢 Attention Software Developers! The #EarlyBird ticket offer for NDC Toronto closes this Monday, Feb 16th 🇨🇦 Join @stevesanderson.bsky.social and 55 other industry experts for 4 days of learning, networking, and fun!
Secure your spot 👉 ndctoronto.com

1 month ago 2 2 0 0