How to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate Transparency @OWASPGLOBAL
How to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate Transparency  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/74/How%20to%20Defend%20Your%20PKI%20Estate%20%28Ivan%20Ristic%2C%20November%202025%29%20FINAL.pdf

On the Internet, all security is controlled by digital certificates, but there is a critical flaw at the heart of our Public Key Infrastructure (PKI) ecosystem: any Certification Authority can issue a certificate for any of your properties without your consent. Recent years have seen development of some mitigation technologies, such as Certification Authority Authorization (CAA) and Certificate Transparency (CT). Together, these technologies enable you to regain control of your digital identities. We've spent several years securing digital estates for a wide range of customers; in this talk, we'll share our experiences to help you understand the threats and give you actionable advice to raise your defenses.

Ivan Ristic
Red Sift
Chief Scientist

Ivan Ristić writes computer security books and builds security products. His book Bulletproof TLS and PKI, the result of more than a decade of research and study, is widely recognised as the de facto SSL/TLS and PKI reference manual. His work on SSL Labs made millions of web sites more secure. Before that, he created ModSecurity, a leading open-source web application firewall. More recently, Ivan founded Hardenize—now part of Red Sift—as a platform for continuous discovery and monitoring of network and PKI infrastructure. He works as Chief Scientist at Red Sift.
@ivanristic
linkedin.com/in/ivanr

Managed by the OWASP® Foundation
owasp.org
How to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate TransparencyExhibitor : Over a Decade of Software Security  What Have We Learned -  Adam BrownOWASP Cornucopia Abuse Case ModelingExploitable In The Wild CVE Appears! But Should We Fix em All?OWASP Global Board of Directors - September 2025OWASP Global Board of Directors - October 2025Plugins Gone Rogue: Attacking Developer Environments202008 August 2020 Global Board MeetingFrom Logs to Defense: Building AI Enhanced XDR Pipelines for Application Level Threats track 1OWASP Global Board of Directors Meeting - July 2025OWASP Top 10 AnnoucementLessons Learned: AppSec Role Based Training 5 Years Ups, Downs, Futures
OWASP Foundation |

How to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate Transparency

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER