<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SSL/TLS | WebPixie Blog</title><description>Posts tagged with SSL/TLS on the WebPixie Blog.</description><link>https://webpixie.io/blog/</link><language>en-gb</language><atom:link href="https://webpixie.io/blog/tag/ssl-tls/rss.xml" rel="self" type="application/rss+xml"/><item><title>A valid TLS certificate didn&apos;t save Virtualizor from a BGP hijack</title><link>https://webpixie.io/blog/post/bgp-hijack-valid-tls-certificate-virtualizor</link><guid isPermaLink="true">https://webpixie.io/blog/post/bgp-hijack-valid-tls-certificate-virtualizor</guid><description>The attacker&apos;s certificate for Virtualizor&apos;s domains was real, correctly chained, and issued by Let&apos;s Encrypt. That&apos;s the actual story: certificate validity checks the cert, not the network path serving it.</description><pubDate>Mon, 14 Sep 2026 08:33:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/bgp-hijack-valid-tls-certificate-virtualizor-feature.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>Chrome 154 will warn on HTTP-only sites: what to check first</title><link>https://webpixie.io/blog/post/chrome-154-http-warning-subdomain-audit</link><guid isPermaLink="true">https://webpixie.io/blog/post/chrome-154-http-warning-subdomain-audit</guid><description>Chrome 154 turns on HTTPS-by-default warnings for everyone in October 2026. Finding your subdomains is the easy part. Knowing which of them actually need fixing before then is the part nobody&apos;s writing about.</description><pubDate>Sat, 12 Sep 2026 20:47:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/chrome-154-http-warning-subdomain-audit-feature.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>OCSP stapling in 2026: what changed and what to do now</title><link>https://webpixie.io/blog/post/ocsp-stapling-2026</link><guid isPermaLink="true">https://webpixie.io/blog/post/ocsp-stapling-2026</guid><description>Let&apos;s Encrypt shut down OCSP entirely in August 2025. Chrome and Firefox both moved revocation checking off the live connection years ago. Most OCSP stapling tutorials still teach it as the default, without saying any of that.</description><pubDate>Tue, 08 Sep 2026 10:15:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/ocsp-stapling-2026-feature.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>Let&apos;s Encrypt rate limits: the operator flowchart</title><link>https://webpixie.io/blog/post/lets-encrypt-rate-limits-2026</link><guid isPermaLink="true">https://webpixie.io/blog/post/lets-encrypt-rate-limits-2026</guid><description>Let&apos;s Encrypt&apos;s shift to 45-day certificates will double daily renewal requests. Here is which rate limit you actually hit, why, how long until it resets, and the one mechanism most automated setups already have that sidesteps the problem entirely.</description><pubDate>Sat, 05 Sep 2026 09:36:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/lets-encrypt-rate-limits-2026-feature.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>Does your SSL monitor actually check the certificate chain?</title><link>https://webpixie.io/blog/post/ssl-monitor-certificate-chain-check</link><guid isPermaLink="true">https://webpixie.io/blog/post/ssl-monitor-certificate-chain-check</guid><description>Most SSL monitoring dashboards show a green check for two things: the TLS handshake succeeded and the certificate has not expired. Neither one confirms the chain is complete, and an incomplete chain fails silently for exactly the clients your monitor never tests.</description><pubDate>Fri, 21 Aug 2026 09:36:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/ssl-monitor-certificate-chain-check-feature.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>ACME Renewal Information: the monitoring blind spot</title><link>https://webpixie.io/blog/post/acme-renewal-information</link><guid isPermaLink="true">https://webpixie.io/blog/post/acme-renewal-information</guid><description>ACME Renewal Information (RFC 9773) lets a CA tell your client to renew earlier than the raw expiry date suggests. Every guide treats it as an ACME-client feature. None treats it as a second signal an external monitor could watch.</description><pubDate>Mon, 20 Jul 2026 20:50:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/08/acme-renewal-information-feature.png" medium="image"/><category>SSL/TLS</category><author>Matt Scott</author></item><item><title>Certificate inventory: skip the spreadsheet</title><link>https://webpixie.io/blog/post/certificate-inventory-ct-logs</link><guid isPermaLink="true">https://webpixie.io/blog/post/certificate-inventory-ct-logs</guid><description>Building a certificate inventory from scratch is unnecessary work. Certificate Transparency logs already record every certificate issued for your domain, in public, for free. Here is how to read that record yourself.</description><pubDate>Sun, 19 Jul 2026 17:02:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/08/certificate-inventory-ct-logs-feature.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>Let&apos;s Encrypt stopped sending expiration emails</title><link>https://webpixie.io/blog/post/lets-encrypt-expiration-emails</link><guid isPermaLink="true">https://webpixie.io/blog/post/lets-encrypt-expiration-emails</guid><description>Let&apos;s Encrypt ended its certificate expiration emails in June 2025. Here is why its own recommended fix does not solve the real problem, and what actually catches a renewal that fails silently.</description><pubDate>Fri, 17 Jul 2026 17:02:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/08/lets-encrypt-expiration-emails-feature-2.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>How to check SSL certificate expiration</title><link>https://webpixie.io/blog/post/check-ssl-certificate-expiration</link><guid isPermaLink="true">https://webpixie.io/blog/post/check-ssl-certificate-expiration</guid><description>Checking an SSL certificate&apos;s expiration takes ten seconds with a browser or openssl. The real problem: certificate lifespans have already dropped to 200 days and reach 47 by 2029, so a once-a-year manual check no longer protects you. Here is how to check, and how to automate it.</description><pubDate>Sat, 13 Jun 2026 13:18:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/07/track-ssl-expiry-dates.png" medium="image"/><category>SSL/TLS</category><category>Monitoring</category><author>Matt Scott</author></item></channel></rss>