Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/74/How%20to%20Defend%20Your%20PKI%20Estate%20%28Ivan%20Ristic%2C%20November%202025%29%20FINAL.pdf
On the Internet, all security is controlled by digital certificates, but there is a critical flaw at the heart of our Public Key Infrastructure (PKI) ecosystem: any Certification Authority can issue a certificate for any of your properties without your consent. Recent years have seen development of some mitigation technologies, such as Certification Authority Authorization (CAA) and Certificate Transparency (CT). Together, these technologies enable you to regain control of your digital identities. We've spent several years securing digital estates for a wide range of customers; in this talk, we'll share our experiences to help you understand the threats and give you actionable advice to raise your defenses.
Ivan Ristic
Red Sift
Chief Scientist
Ivan Ristić writes computer security books and builds security products. His book Bulletproof TLS and PKI, the result of more than a decade of research and study, is widely recognised as the de facto SSL/TLS and PKI reference manual. His work on SSL Labs made millions of web sites more secure. Before that, he created ModSecurity, a leading open-source web application firewall. More recently, Ivan founded Hardenize—now part of Red Sift—as a platform for continuous discovery and monitoring of network and PKI infrastructure. He works as Chief Scientist at Red Sift.
@ivanristic
linkedin.com/in/ivanr
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/74/How%20to%20Defend%20Your%20PKI%20Estate%20%28Ivan%20Ristic%2C%20November%202025%29%20FINAL.pdf
On the Internet, all security is controlled by digital certificates, but there is a critical flaw at the heart of our Public Key Infrastructure (PKI) ecosystem: any Certification Authority can issue a certificate for any of your properties without your consent. Recent years have seen development of some mitigation technologies, such as Certification Authority Authorization (CAA) and Certificate Transparency (CT). Together, these technologies enable you to regain control of your digital identities. We've spent several years securing digital estates for a wide range of customers; in this talk, we'll share our experiences to help you understand the threats and give you actionable advice to raise your defenses.
Ivan Ristic
Red Sift
Chief Scientist
Ivan Ristić writes computer security books and builds security products. His book Bulletproof TLS and PKI, the result of more than a decade of research and study, is widely recognised as the de facto SSL/TLS and PKI reference manual. His work on SSL Labs made millions of web sites more secure. Before that, he created ModSecurity, a leading open-source web application firewall. More recently, Ivan founded Hardenize—now part of Red Sift—as a platform for continuous discovery and monitoring of network and PKI infrastructure. He works as Chief Scientist at Red Sift.
@ivanristic
linkedin.com/in/ivanr
Managed by the OWASP® Foundation
owasp.org










