Skip to content

Instantly share code, notes, and snippets.

@toddhgardner
Created December 19, 2025 19:20
Show Gist options
  • Select an option

  • Save toddhgardner/9a258820df0ae97825b7dca1c6198dd2 to your computer and use it in GitHub Desktop.

Select an option

Save toddhgardner/9a258820df0ae97825b7dca1c6198dd2 to your computer and use it in GitHub Desktop.
Abstract for a new talk on WebPKI in 2026

Everything you learned about SSL is deprecated

Remember your first HTTPS server? RSA keys, year+ certificates, and some openssl incantation you copied from StackOverflow. That's all outdated now.

TLS 1.3 threw out decades of cipher complexity. Snowden leaks moved Perfect Forward Secrecy from optional to mandatory. Let's Encrypt made certificates a free API call. And browser vendors are pushing certificate lifetimes down to 47 days.

This talk is a tour of modern SSL TLS. We'll cover what changed, why it changed, and what breaks if you don't make updates.

@toddhgardner
Copy link
Author

Thanks so much for the feedback @robconery!

What has surprised me in the past year is how much infrastructure still deals with certificates directly. Not so much the new systems built in the cloud, but a huge number of important systems still running on-prem and requiring RSA certificates for obscure reasons. This talk is targeting those folks primarily, and everything that changed while they weren't paying attention.

asymmetric keys and quantum is definitely in scope for the talk.

How about this for a better hook?

Most of us learned certificates through Stack Overflow and tribal knowledge. Enough to make the padlock appear, not enough to really explain why. That was just fine when certificates lasted a year, but it that's about to end.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment