Data Privacy Conference

On building privacy in engineering and product processes.

Michael W Lucas

TLS in 2021

Submitted Apr 2, 2021

Transport Layer Security: everybody needs it, but few of us understand it. TLS is not just about getting the lock icon in the browser address bar. It’s perhaps the most frequently misconfigured protocol on the Internet.

This talk takes you through:
• How TLS works
• What TLS provides, and what it doesn’t
• How applications wrap unencrypted connections inside TLS
• Assessing TLS configurations
• The Automated Certificate Management Environment (ACME) protocol
• Using Let’s Encrypt to automatically maintain TLS certificates
• Online Certificate Status Protocol
• The Realities of Certificate Revocation
• CAA, HSTS, and Certificate Transparency
• Why you shouldn’t run your own CA, and hints on how to do it anyway


