Sign in

Andrew Ayer

@agwa.name
232 followers 66 following 11 posts

Bootstrapped founder of SSLMate (sslmate.com). Making SSL certificates easier and doing #WebPKI and #CertificateTransparency research on the side. Blog: www.agwa.name He/him

PostsRepliesMedia
Andrew Ayer @agwa.name · 24/09/2026
macOS Can't Clone "Dumb" Git Repositories Over HTTP/2 www.agwa.name/blog/post/ma...
agwa.name
macOS Can't Clone "Dumb" Git Repositories Over HTTP/2
macOS 27 ships a 2 year old version of libcurl with a git-impacting bug
110
Andrew Ayer @agwa.name · 29/04/2026
FastCGI: 30 Years Old and Still the Better Protocol for Reverse Proxies www.agwa.name/blog/post/fa...
agwa.name
FastCGI: 30 Years Old and Still the Better Protocol for Reverse Proxies
For FastCGI's 30th birthday, let's look at how it avoids the security problems inherent in HTTP reverse proxying
011
Andrew Ayer @agwa.name · 19/02/2026
New blog post: Why IP Address Certificates Are Dangerous and Usually Unnecessary www.agwa.name/blog/post/ip...
agwa.name
Why IP Address Certificates Are Dangerous and Usually Unnecessary
Unless you're operating a DNS-over-TLS or DNS-over-HTTPS resolver, you should not use IP address certificates.
120
Reposted by Andrew Ayer
noallusions.bsky.social @noallusions.bsky.social · 04/01/2026
Add GoDaddy (shocker, i know) to that list of CAs. A relative reached out to me for help because their biz website was getting flagged in Safari. New SSL cert issued by GoDaddy on 12/22 and one of the SCTs on the cert is for Digicert Sphinx 2027h1.
011
Andrew Ayer @agwa.name · 10/12/2025
New blog post: Certificate Authorities Are Once Again Issuing Certificates That Don't Work www.agwa.name/blog/post/ca...
agwa.name
Certificate Authorities Are Once Again Issuing Certificates That Don't Work
I've detected 16 CAs issuing certificates which rely on CT logs that are not recognized by all browsers
153
Andrew Ayer @agwa.name · 03/11/2025
Google just suspended SSLMate's Google Cloud account for the third time: www.agwa.name/blog/post/go... The obvious fail is Google's trigger-happy account suspensions, but the more important fail is that Google is disincentivizing the secure options for cross-provider access with Google Cloud. 1/4
agwa.name
Google Just Suspended My Company's Google Cloud Account for the Third Time
262
Andrew Ayer @agwa.name · 29/10/2025
New blog post: I'm Independently Verifying Go's Reproducible Builds: www.agwa.name/blog/post/ve...
agwa.name
I'm Independently Verifying Go's Reproducible Builds
Introducing Source Spotter, a Go Checksum Database auditor and Go toolchain reproducer
1297
Andrew Ayer @agwa.name · 29/08/2025
New blog post: SQLite's Durability Settings are a Mess www.agwa.name/blog/post/sq...
agwa.name
SQLite's Durability Settings are a Mess
Is SQLite durable by default? What settings guarantee durability? The documentation and even comments from its creator give conflicting answers.
141
Reposted by Andrew Ayer
Lucas Azzola @azzola.dev · 07/01/2025
Turns out Alpine Linux has a copy of the same script from curl! I've raised an issue in their issue tracker: gitlab.alpinelinux.org/alpine/ca-ce...
gitlab.alpinelinux.org
ca-certificates bundle incorrectly excludes root CAs with CKA_NSS_SERVER_DISTRUST_AFTER (#6) · Issues · alpine / ca-certificates · GitLab
The build script in ca-certificates incorrectly omits CA roots with a "DistrustAfter" attribute. See this fix in curl: https://github.com/curl/curl/commit/448df98d9280b3290ecf63e5fc9452d487f41a7c#diff...
031
Andrew Ayer @agwa.name · 25/11/2024
I recently investigated how the Entrust distrust would be unintentionally disruptive to non-browser clients: sslmate.com/blog/post/en... Good news since then: curl has fixed their CA bundle generator, a fix is pending for mkcert.org, and python-certifi is pausing releases until mkcert is fixed!
sslmate.com
The Entrust Distrust Will Be More Disruptive Than Intended
Non-browser clients don't properly handle the Distrust After date
152