# certificate

Published articles for certificate.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## New Release: Tor Browser 15.0.23

DevFeed: [New Release: Tor Browser 15.0.23](<https://devfeed.tech/articles/new-release-tor-browser-15-0-23-53189.md>)

Original publisher: [Read original article](<https://blog.torproject.org/new-release-tor-browser-15023/>)

Author: ma1

Published: 2026-09-15T00:00:00Z

Content type: release

Language: en

Sources: [Tor Project blog](<https://devfeed.tech/sources/tor-project-blog.md>)

Topics: [tor](<https://devfeed.tech/topics/tor.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Security](<https://devfeed.tech/topics/security.md>), [browser](<https://devfeed.tech/topics/browser.md>), [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>), [changelog](<https://devfeed.tech/topics/changelog.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [applications](<https://devfeed.tech/tags/applications.md>), [browser](<https://devfeed.tech/tags/browser.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [digicert](<https://devfeed.tech/tags/digicert.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [tor](<https://devfeed.tech/tags/tor.md>), [version](<https://devfeed.tech/tags/version.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Tor Browser 15.0.23 is available with Firefox security updates and other platform-specific changes. The release also documents an expired DigiCert EV certificate affecting fresh Windows installations of earlier versions, along with a temporary workaround and a full changelog.

### Source excerpt

Tor Browser 15.0.23 is now available from the Tor Browser download page and also from our distribution directory. This version includes important security updates to Firefox. Windows Package Signature Issue The DigiCert EV code-signing certificate we use to sign Windows installation packages is expired since September 1st and we are currently in the process to renew it. Unfortunately, this process is delayed and not yet complete. This has caused Windows users trying to install Tor Browser 15.0.21 and 15.0.22 from scratch to receive "bad signature" warnings. As a temporary work-around, for Windows only we're keeping Tor Browser 15.0.20 (the latest correctly signed version) listed on our download page, relying on automatic updates (which are signed with a different key, not involving this expired certificate) to bring Windows users to the current version. Users who prefer to download the latest version directly, ignoring the certificate expiration warning, can download it from https://dist.torproject.org/torbrowser/15.0.23/. Send us your feedback If you find a bug or have a suggestion for how we could improve this release, please let us know. Full changelog The full changelog since Tor Browser 15.0.22 is: All Platforms Updated NoScript to 13.6.33.1984 Bug tor-browser#45296: (H1) SharedWorker Identity Mismatch allows WebAssembly execution at Safer Bug tor-browser#45297: (H1) Missing setHTMLUnsafe hook leaves a permanent WebAssembly-capable child realm at Safer Bug tor-browser#45299: Backport Security Fixes from Firefox 156 Bug tor-browser#45303: Rebase Tor Browser stable onto 140.16.0esr Bug tor-browser-build#41875: Update relprep.py for the new versions.ini URL Windows + macOS + Linux Updated Firefox to 140.16.0esr Linux Bug tor-browser#44996: Change the 32-bit linux message to the expired version for the final 15.0 release Android Updated GeckoView to 140.16.0esr Build System All Platforms Bug tor-browser-build#41871: Update downloads repository references in relprep

## Azure SDK Release (July 2026)

DevFeed: [Azure SDK Release (July 2026)](<https://devfeed.tech/articles/azure-sdk-release-july-2026-50029.md>)

Original publisher: [Read original article](<https://devblogs.microsoft.com/azure-sdk/azure-sdk-release-july-2026/>)

Author: Justin Bettencourt

Published: 2026-07-29T17:18:25Z

Content type: release

Language: en

Sources: [Azure SDK Blog](<https://devfeed.tech/sources/azure-sdk-blog.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [Python](<https://devfeed.tech/topics/python.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [AWS Certificate Manager](<https://devfeed.tech/topics/aws-certificate-manager.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [azure](<https://devfeed.tech/tags/azure.md>), [azure-sdk](<https://devfeed.tech/tags/azure-sdk.md>), [blog](<https://devfeed.tech/tags/blog.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [developers](<https://devfeed.tech/tags/developers.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [notes](<https://devfeed.tech/tags/notes.md>), [python](<https://devfeed.tech/tags/python.md>), [release](<https://devfeed.tech/tags/release.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [releases](<https://devfeed.tech/tags/releases.md>), [rust](<https://devfeed.tech/tags/rust.md>), [sdk](<https://devfeed.tech/tags/sdk.md>)

### AI overview

The July 2026 Azure SDK release introduces a Rust crate for building user-delegation Shared Access Signatures for Azure Storage. It also brings stable Python management libraries for App Service domains and certificates, Resource Health, and Data Boundaries, alongside initial stable and beta releases for Java, Python, and Rust libraries.

### Source excerpt

Azure SDK releases every month. In this post, you'll find this month's highlights and release notes. The post Azure SDK Release (July 2026) appeared first on Azure SDK Blog.

## Zabbix and the Docker API, Part 1: Inspect

DevFeed: [Zabbix and the Docker API, Part 1: Inspect](<https://devfeed.tech/articles/zabbix-and-the-docker-api-part-1-inspect-45091.md>)

Original publisher: [Read original article](<https://blog.zabbix.com/zabbix-and-the-docker-api-part-1-inspect/32860/>)

Author: Janis Eidaks

Published: 2026-04-22T08:04:04Z

Content type: tutorial

Language: en

Sources: [Zabbix Blog](<https://devfeed.tech/sources/zabbix-blog.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [API](<https://devfeed.tech/topics/api.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Security](<https://devfeed.tech/topics/security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-metrics](<https://devfeed.tech/tags/api-metrics.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [data-collection](<https://devfeed.tech/tags/data-collection.md>), [docker](<https://devfeed.tech/tags/docker.md>), [handy-tips](<https://devfeed.tech/tags/handy-tips.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [tls](<https://devfeed.tech/tags/tls.md>), [zabbix](<https://devfeed.tech/tags/zabbix.md>)

### AI overview

A tutorial on configuring Zabbix to securely collect Docker API metrics using the Zabbix HTTP agent and certificate authentication. It covers securing Docker API access, generating certificates, configuring TLS-related settings, and connecting the Zabbix server.

### Source excerpt

In this blog post, I will show you how to configure Zabbix to securely gather Docker API metrics using the Zabbix HTTP agent item with certificate authentication. This guide will cover configuring the Docker API and the Zabbix server side to gather data more securely. Getting the data to Zabbix from the Docker API By [...] The post Zabbix and the Docker API, Part 1: Inspect appeared first on Zabbix Blog.

## Qdrant Academy Expands with Official Certification

DevFeed: [Qdrant Academy Expands with Official Certification](<https://devfeed.tech/articles/qdrant-academy-expands-with-official-certification-46706.md>)

Original publisher: [Read original article](<https://qdrant.tech/blog/qdrant-certification-launch/>)

Author: info@qdrant.tech (Andrey Vasnetsov)

Published: 2026-01-28T00:00:00Z

Content type: release

Language: en

Sources: [Qdrant Blog on Qdrant - Vector Search Engine](<https://devfeed.tech/sources/qdrant-blog-on-qdrant-vector-search-engine.md>)

Topics: [Qdrant](<https://devfeed.tech/topics/qdrant.md>), [AI search](<https://devfeed.tech/topics/ai-search.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [recommendation systems](<https://devfeed.tech/topics/recommendation-systems.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [quantization](<https://devfeed.tech/topics/quantization.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-search](<https://devfeed.tech/tags/ai-search.md>), [approximate-nearest-neighbor-search](<https://devfeed.tech/tags/approximate-nearest-neighbor-search.md>), [bert](<https://devfeed.tech/tags/bert.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [certification](<https://devfeed.tech/tags/certification.md>), [developers](<https://devfeed.tech/tags/developers.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fasttext](<https://devfeed.tech/tags/fasttext.md>), [hnsw](<https://devfeed.tech/tags/hnsw.md>), [image-search](<https://devfeed.tech/tags/image-search.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [knn-algorithm](<https://devfeed.tech/tags/knn-algorithm.md>), [learning](<https://devfeed.tech/tags/learning.md>), [matching](<https://devfeed.tech/tags/matching.md>), [neural-network](<https://devfeed.tech/tags/neural-network.md>), [qdrant](<https://devfeed.tech/tags/qdrant.md>), [rag](<https://devfeed.tech/tags/rag.md>), [recommendation-systems](<https://devfeed.tech/tags/recommendation-systems.md>), [recommender-system](<https://devfeed.tech/tags/recommender-system.md>), [saas](<https://devfeed.tech/tags/saas.md>), [simaes-networks](<https://devfeed.tech/tags/simaes-networks.md>), [similarity](<https://devfeed.tech/tags/similarity.md>), [transformer](<https://devfeed.tech/tags/transformer.md>), [vector-search](<https://devfeed.tech/tags/vector-search.md>), [vector-search-engine](<https://devfeed.tech/tags/vector-search-engine.md>), [vectors](<https://devfeed.tech/tags/vectors.md>), [word2vec](<https://devfeed.tech/tags/word2vec.md>)

### AI overview

Qdrant has launched its first official Qdrant Essentials certification through Qdrant Academy. The course and exam validate knowledge of vector search architecture, filtering, hybrid retrieval, and production optimization for RAG and recommendation systems.

### Source excerpt

Since we first announced Qdrant Academy, our mission has been to provide developers with more than just documentation. We wanted to build a structured path to mastering vector search. As the AI search landscape matures, the distinction between a simple storage layer and a high-performance vector search engine has become the defining factor in production-grade RAG and recommendation systems. Today, we are thrilled to take the next step in that mission. It's time to move from learning to proving your expertise with the launch of our first official certification.

## Understanding email encryption

DevFeed: [Understanding email encryption](<https://devfeed.tech/articles/understanding-email-encryption-51565.md>)

Original publisher: [Read original article](<https://www.fastmail.com/blog/email-encryption/>)

Author: Neil Jenkins

Published: 2025-12-17T00:00:01Z

Content type: article

Language: en

Sources: [Fastmail Blog](<https://devfeed.tech/sources/fastmail-blog.md>)

Topics: [email](<https://devfeed.tech/topics/email.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [certificate](<https://devfeed.tech/tags/certificate.md>), [email](<https://devfeed.tech/tags/email.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [password](<https://devfeed.tech/tags/password.md>), [privacy-security](<https://devfeed.tech/tags/privacy-security.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains that email encryption can protect against different threats at different stages. It outlines common risks such as account compromise, malware, data breaches, and network eavesdropping, then describes how TLS encrypts connections between an email client and provider and how certificates and trusted Certificate Authorities help verify the provider's identity.

### Source excerpt

Encrypted email sounds good, but what does it really mean? Email can be encrypted in many different ways, at different times, for different purposes. Each protects against different threats, and may have downsides to be weighed up. Understanding your options helps you make informed choices about your privacy and security. What are you protecting against? Before diving into encryption methods, it's worth asking: what threats actually matter for your email? For most people, the realistic concerns are: Account compromise: phishing or password reuse giving attackers access to your account Mistaken spam detection: causing important mail to go missing Malware: getting a virus via email, either linked or as an attachment Accidental deletion: losing vital data due to human error Far less common, although also important, are: Network eavesdropping: someone on your WiFi or ISP intercepting your traffic Data breaches: attackers gaining access to stored email through a security vulnerability Physical theft: stolen devices or hard drives exposing your data For a smaller number of people -- journalists protecting sources, activists in hostile countries, or those facing sophisticated adversaries -- the threat model expands to include insider threats at providers and legal compulsion by governments. Different encryption approaches help protect (or may even hinder protection) against subsets of these threats, and understanding this helps you choose the right balance. Encrypting the connection to your email provider Whenever you connect to your email provider, TLS (Transport Layer Security) encrypts everything between your device and the server. This protects you from eavesdroppers on your local WiFi network, your ISP, and anyone monitoring network traffic between you and your email service. This standard has been widely adopted and modernised, the latest version being TLS 1.3, which mandates the strongest ciphers and is the foundation of today's secure internet. But encryption alone i

## Observability in Quarkus 3

DevFeed: [Observability in Quarkus 3](<https://devfeed.tech/articles/observability-in-quarkus-3-43939.md>)

Original publisher: [Read original article](<https://quarkus.io/blog/quarkus-observability-3-3/>)

Author: Bruno Baptista

Published: 2023-09-20T00:00:00Z

Content type: release

Language: en

Sources: [Quarkus - Supersonic Subatomic Java](<https://devfeed.tech/sources/quarkus-supersonic-subatomic-java.md>)

Topics: [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [observability](<https://devfeed.tech/topics/observability.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [tracing](<https://devfeed.tech/topics/tracing.md>), [gRPC](<https://devfeed.tech/topics/grpc.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [certificate](<https://devfeed.tech/tags/certificate.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [developers](<https://devfeed.tech/tags/developers.md>), [grpc](<https://devfeed.tech/tags/grpc.md>), [http](<https://devfeed.tech/tags/http.md>), [observability](<https://devfeed.tech/tags/observability.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [tracing](<https://devfeed.tech/tags/tracing.md>)

### AI overview

Quarkus 3.3 improves observability through updates to its OpenTelemetry extension, including better development-mode behavior, additional extension points, simpler JDBC tracing activation, HTTP exporter support, TLS and custom certificate support, and customizable propagation headers.

### Source excerpt

Observability in Quarkus Observability on a software system can be described as the capability to allow a human to ask and answer questions. To enable developers and support engineers in understanding how their applications behave, Quarkus 3.3 includes many improvements to its main observability related extensions: quarkus-opentelemetry (tracing) quarkus-micrometer (metrics) OpenTelemetry OpenTelemetry tracing is used to understand the flow of requests as they traverse through multiple services. The quarkus-opentelemetry extension already had a major upgrade on Quarkus 3.0, where the configurations aligned with the ones used by the OpenTelemetry (OTel) community. This made available many configurations that were not previously available in Quarkus. Other improvements include: The OpenTelemetry extension can be used in dev mode and now reloads properly. OTel Service Provider Interface (SPI) hooks for Sampler and SpanExporter were made available along with the existing user implementations with CDI for many OTel classes: IdGenerator, Resource attributes, Sampler and SpanProcessor. At the same time, the JDBC tracing activation was made simpler, just requiring the use of a property: quarkus.datasource.jdbc.telemetry=true On Quarkus 3.3 many improvements were made to the quarkus-opentelemetry extension. The most impactful ones are Removal of the OkHttp dependency In previous versions of the Quarkus exporter used the upstream OTel libraries and leveraged the OkHttp library to send the spans to the OTel Collector. This unnecessary dependency was removed and replaced by Quarkus specific Vert.x GRPC and HTTP clients. As previously, the exporter continues to be automatically wired with CDI, that's why the quarkus.otel.traces.exporter property defaults to cdi on Quarkus 3+. Exporter support fot the HTTP protocol Up until Quarkus 3.2, the OTel exporter could only use the GRPC protocol, while Quarkus now supports HTTP as well. To use the new HTTP protocol, the quarkus.otel.expor

## Why I switched from Netlify back to GitHub Pages

DevFeed: [Why I switched from Netlify back to GitHub Pages](<https://devfeed.tech/articles/why-i-switched-from-netlify-back-to-github-pages-46494.md>)

Original publisher: [Read original article](<https://eugeneyan.com//writing/netlify-back-to-github-pages/>)

Author: Eugene Yan

Published: 2020-10-21T00:00:00Z

Content type: opinion

Language: en

Sources: [Eugene Yan](<https://devfeed.tech/sources/eugene-yan.md>)

Topics: [GitHub Pages](<https://devfeed.tech/topics/github-pages.md>), [Netlify](<https://devfeed.tech/topics/netlify.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>), [domain](<https://devfeed.tech/topics/domain.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Jekyll](<https://devfeed.tech/topics/jekyll.md>)

Tags: [certificate](<https://devfeed.tech/tags/certificate.md>), [dns](<https://devfeed.tech/tags/dns.md>), [email-security](<https://devfeed.tech/tags/email-security.md>), [github-pages](<https://devfeed.tech/tags/github-pages.md>), [me](<https://devfeed.tech/tags/me.md>), [misc](<https://devfeed.tech/tags/misc.md>), [netlify](<https://devfeed.tech/tags/netlify.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The author describes switching a personal site from GitHub Pages to Netlify and back again. Netlify offered rollbacks, broader Jekyll plugin support, and A/B testing, but DNS migration problems caused bounced email and certificate errors, while the free build-time limit became restrictive.

### Source excerpt

DNS server snafus led to email & security issues. Also, limited free build minutes monthly.

## Direct encrypted traffic from IBM Cloud Kubernetes Service Ingress to Istio Ingress Gateway

DevFeed: [Direct encrypted traffic from IBM Cloud Kubernetes Service Ingress to Istio Ingress Gateway](<https://devfeed.tech/articles/direct-encrypted-traffic-from-ibm-cloud-kubernetes-service-ingress-to-istio-ingress-gateway-48703.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2020/alb-ingress-gateway-iks/>)

Author: Vadim Eisenberg (IBM)

Published: 2020-05-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [ibm](<https://devfeed.tech/topics/ibm.md>), [gateway](<https://devfeed.tech/topics/gateway.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [private key](<https://devfeed.tech/topics/private-key.md>)

Tags: [application-load-balancer](<https://devfeed.tech/tags/application-load-balancer.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [clients](<https://devfeed.tech/tags/clients.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cluster](<https://devfeed.tech/tags/cluster.md>), [configure](<https://devfeed.tech/tags/configure.md>), [dns](<https://devfeed.tech/tags/dns.md>), [domain](<https://devfeed.tech/tags/domain.md>), [encrypted](<https://devfeed.tech/tags/encrypted.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [iks](<https://devfeed.tech/tags/iks.md>), [ingress](<https://devfeed.tech/tags/ingress.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [mutual-tls](<https://devfeed.tech/tags/mutual-tls.md>), [routing](<https://devfeed.tech/tags/routing.md>), [sds-credentials](<https://devfeed.tech/tags/sds-credentials.md>), [secret](<https://devfeed.tech/tags/secret.md>), [services](<https://devfeed.tech/tags/services.md>), [traffic-management](<https://devfeed.tech/tags/traffic-management.md>)

### AI overview

This tutorial explains how to configure the IBM Cloud Kubernetes Service Application Load Balancer to route traffic to an Istio ingress gateway. It covers using mutual TLS, certificates, private keys, DNS subdomains, and Kubernetes secrets while supporting both mesh and non-mesh services during migration.

### Source excerpt

In this blog post I show how to configure the Ingress Application Load Balancer (ALB) on IBM Cloud Kubernetes Service (IKS) to direct traffic to the Istio ingress gateway, while securing the traffic between them using mutual TLS authentication. When you use IKS without Istio, you may control your ingress traffic using the provided ALB. This ingress-traffic routing is configured using a Kubernetes Ingress resource with ALB-specific annotations. IKS provides a DNS domain name, a TLS certificate that matches the domain, and a private key for the certificate. IKS stores the certificates and the private key in a Kubernetes secret. When you start using Istio in your IKS cluster, the recommended method to send traffic to your Istio enabled workloads is by using the Istio Ingress Gateway instead of using the Kubernetes Ingress. One of the main reasons to use the Istio ingress gateway is the fact the ALB provided by IKS will not be able to communicate directly with the services inside the mesh when you enable STRICT mutual TLS. During your transition to having only Istio ingress gateway as your main entry point, you can continue to use the traditional Ingress for non-Istio services while using the Istio ingress gateway for services that are part of the mesh. IKS provides a convenient way for clients to access Istio ingress gateway by letting you register a new DNS subdomain for the Istio gateway's IP with an IKS command. The domain is in the following format: <cluster_name>-<globally_unique_account_HASH>-0001.<region>.containers.appdomain.cloud, for example mycluster-a1b2cdef345678g9hi012j3kl4567890-0001.us-south.containers.appdomain.cloud. In the same way as for the ALB domain, IKS provides a certificate and a private key, storing them in another Kubernetes secret. This blog describes how you can chain together the IKS Ingress ALB and the Istio ingress gateway to send traffic to your Istio enabled workloads while being able to continue using the ALB specific features and th

## Provision a certificate and key for an application without sidecars

DevFeed: [Provision a certificate and key for an application without sidecars](<https://devfeed.tech/articles/provision-a-certificate-and-key-for-an-application-without-sidecars-48716.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2020/proxy-cert/>)

Author: Lei Tang (Google)

Published: 2020-03-25T00:00:00Z

Content type: tutorial

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [private key](<https://devfeed.tech/topics/private-key.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [kubectl](<https://devfeed.tech/topics/kubectl.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>)

Tags: [certificate](<https://devfeed.tech/tags/certificate.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [mutual-tls](<https://devfeed.tech/tags/mutual-tls.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [service-mesh](<https://devfeed.tech/tags/service-mesh.md>), [services](<https://devfeed.tech/tags/services.md>), [sidecar](<https://devfeed.tech/tags/sidecar.md>), [sidecars](<https://devfeed.tech/tags/sidecars.md>)

### AI overview

This tutorial explains how to provision an application certificate and private key without using a sidecar to manage traffic. It describes deploying an Istio sidecar solely to obtain certificates through the CSR flow and share them with an application through a mounted tmpfs file, using Prometheus as the example.

### Source excerpt

The following information describes an experimental feature, which is intended for evaluation purposes only. Istio sidecars obtain their certificates using the secret discovery service. A service in the service mesh may not need (or want) an Envoy sidecar to handle its traffic. In this case, the service will need to obtain a certificate itself if it wants to connect to other TLS or mutual TLS secured services. For a service with no need of a sidecar to manage its traffic, a sidecar can nevertheless still be deployed only to provision the private key and certificates through the CSR flow from the CA and then share the certificate with the service through a mounted file in tmpfs. We have used Prometheus as our example application for provisioning a certificate using this mechanism. In the example application (i.e., Prometheus), a sidecar is added to the Prometheus deployment by setting the flag .Values.prometheus.provisionPrometheusCert to true (this flag is set to true by default in an Istio installation). This deployed sidecar will then request and share a certificate with Prometheus. The key and certificate provisioned for the example application are mounted in the directory /etc/istio-certs/. We can list the key and certificate provisioned for the application by running the following command: $ kubectl exec -it `kubectl get pod -l app=prometheus -n istio-system -o jsonpath='{.items[0].metadata.name}'` -c prometheus -n istio-system -- ls -la /etc/istio-certs/ The output from the above command should include non-empty key and certificate files, similar to the following: -rwxr-xr-x 1 root root 2209 Feb 25 13:06 cert-chain.pem -rwxr-xr-x 1 root root 1679 Feb 25 13:06 key.pem -rwxr-xr-x 1 root root 1054 Feb 25 13:06 root-cert.pem If you want to use this mechanism to provision a certificate for your own application, take a look at our Prometheus example application and simply follow the same pattern.

## DNS Certificate Management

DevFeed: [DNS Certificate Management](<https://devfeed.tech/articles/dns-certificate-management-48682.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2019/dns-cert/>)

Author: Lei Tang (Google)

Published: 2019-11-14T00:00:00Z

Content type: article

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [certificates](<https://devfeed.tech/topics/certificates.md>), [istio](<https://devfeed.tech/topics/istio.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [control-plane](<https://devfeed.tech/topics/control-plane.md>), [Security](<https://devfeed.tech/topics/security.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [1-4](<https://devfeed.tech/tags/1-4.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [certificate-management](<https://devfeed.tech/tags/certificate-management.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [citadel](<https://devfeed.tech/tags/citadel.md>), [control-plane](<https://devfeed.tech/tags/control-plane.md>), [dns](<https://devfeed.tech/tags/dns.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [security](<https://devfeed.tech/tags/security.md>), [services](<https://devfeed.tech/tags/services.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This article describes an Istio 1.4 feature for securely provisioning and managing DNS certificates signed by the Kubernetes CA. The approach removes the dependency on Citadel, avoids maintaining a private signing key, and simplifies root certificate distribution to TLS clients.

### Source excerpt

By default, Citadel manages the DNS certificates of the Istio control plane. Citadel is a large component that maintains its own private signing key, and acts as a Certificate Authority (CA). New in Istio 1.4, we introduce a feature to securely provision and manage DNS certificates signed by the Kubernetes CA, which has the following advantages. Lighter weight DNS certificate management with no dependency on Citadel. Unlike Citadel, this feature doesn't maintain a private signing key, which enhances security. Simplified root certificate distribution to TLS clients. Clients no longer need to wait for Citadel to generate and distribute its CA certificate. The following diagram shows the architecture of provisioning and managing DNS certificates in Istio. Chiron is the component provisioning and managing DNS certificates in Istio. The architecture of provisioning and managing DNS certificates in Istio To try this new feature, refer to the DNS certificate management task.

## Secure Webhook Management

DevFeed: [Secure Webhook Management](<https://devfeed.tech/articles/secure-webhook-management-48701.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2019/webhook/>)

Author: Lei Tang (Google)

Published: 2019-11-14T00:00:00Z

Content type: release

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [certificate](<https://devfeed.tech/tags/certificate.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [istio](<https://devfeed.tech/tags/istio.md>), [istioctl](<https://devfeed.tech/tags/istioctl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [security](<https://devfeed.tech/tags/security.md>), [services](<https://devfeed.tech/tags/services.md>), [webhook](<https://devfeed.tech/tags/webhook.md>)

### AI overview

This article describes Istio 1.4's more secure webhook management. It explains how istioctl takes over webhook configuration from Galley and the sidecar injector, reduces their privileges, and verifies webhook server readiness and certificate chains before configuration.

### Source excerpt

Istio has two webhooks: Galley and the sidecar injector. Galley validates Kubernetes resources and the sidecar injector injects sidecar containers into Istio. By default, Galley and the sidecar injector manage their own webhook configurations. This can pose a security risk if they are compromised, for example, through buffer overflow attacks. Configuring a webhook is a highly privileged operation as a webhook may monitor and mutate all Kubernetes resources. In the following example, the attacker compromises Galley and modifies the webhook configuration of Galley to eavesdrop on all Kubernetes secrets (the clientConfig is modified by the attacker to direct the secrets resources to a service owned by the attacker). An example attack To protect against this kind of attack, Istio 1.4 introduces a new feature to securely manage webhooks using istioctl: istioctl, instead of Galley and the sidecar injector, manage the webhook configurations. Galley and the sidecar injector are de-privileged so even if they are compromised, they will not be able to alter the webhook configurations. Before configuring a webhook, istioctl will verify the webhook server is up and that the certificate chain used by the webhook server is valid. This reduces the errors that can occur before a server is ready or if a server has invalid certificates. To try this new feature, refer to the Istio webhook management task.

## Change in Secret Discovery Service in Istio 1.3

DevFeed: [Change in Secret Discovery Service in Istio 1.3](<https://devfeed.tech/articles/change-in-secret-discovery-service-in-istio-1-3-48699.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2019/trustworthy-jwt-sds/>)

Author: Phillip Quy Le (Google)

Published: 2019-09-10T00:00:00Z

Content type: release

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [API](<https://devfeed.tech/topics/api.md>), [api server](<https://devfeed.tech/topics/api-server.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [version](<https://devfeed.tech/topics/version.md>), [Gke](<https://devfeed.tech/topics/gke.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [file](<https://devfeed.tech/topics/file.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-server](<https://devfeed.tech/tags/api-server.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [change](<https://devfeed.tech/tags/change.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [discovery](<https://devfeed.tech/tags/discovery.md>), [gke](<https://devfeed.tech/tags/gke.md>), [istio](<https://devfeed.tech/tags/istio.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [mount](<https://devfeed.tech/tags/mount.md>), [nodeagent](<https://devfeed.tech/tags/nodeagent.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [pki](<https://devfeed.tech/tags/pki.md>), [sds](<https://devfeed.tech/tags/sds.md>), [secret](<https://devfeed.tech/tags/secret.md>), [secret-discovery-service](<https://devfeed.tech/tags/secret-discovery-service.md>), [security](<https://devfeed.tech/tags/security.md>), [services](<https://devfeed.tech/tags/services.md>), [signing](<https://devfeed.tech/tags/signing.md>), [token](<https://devfeed.tech/tags/token.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Istio 1.3 changes its Secret Discovery Service to use trustworthy Kubernetes JWTs when issuing certificates for workload instances. The article explains the Kubernetes version requirements, platform-specific configuration considerations, and the file-mount fallback for platforms without trustworthy JWT support.

### Source excerpt

In Istio 1.3, we are taking advantage of improvements in Kubernetes to issue certificates for workload instances more securely. When a Citadel Agent sends a certificate signing request to Citadel to get a certificate for a workload instance, it includes the JWT that the Kubernetes API server issued representing the service account of the workload instance. If Citadel can authenticate the JWT, it extracts the service account name needed to issue the certificate for the workload instance. Before Kubernetes 1.12, the Kubernetes API server issues JWTs with the following issues: The tokens don't have important fields to limit their scope of usage, such as aud or exp. See Bound Service Tokens for more info. The tokens are mounted onto all the pods without a way to opt-out. See Service Account Token Volumes for motivation. Kubernetes 1.12 introduces trustworthy JWTs to solve these issues. However, support for the aud field to have a different value than the API server audience didn't become available until Kubernetes 1.13. To better secure the mesh, Istio 1.3 only supports trustworthy JWTs and requires the value of the aud field to be istio-ca when you enable SDS. Before upgrading your Istio deployment to 1.3 with SDS enabled, verify that you use Kubernetes 1.13 or later. Make the following considerations based on your platform of choice: GKE: Upgrade your cluster version to at least 1.13. On-prem Kubernetes and GKE on-prem: Add extra configurations to your Kubernetes. You may also want to refer to the api-server page for the most up-to-date flag names. For other platforms, check with your provider. If your vendor does not support trustworthy JWTs, you will need to fall back to the file-mount approach to propagate the workload keys and certificates in Istio 1.3.

## Extending Istio Self-Signed Root Certificate Lifetime

DevFeed: [Extending Istio Self-Signed Root Certificate Lifetime](<https://devfeed.tech/articles/extending-istio-self-signed-root-certificate-lifetime-48697.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2019/root-transition/>)

Author: Oliver Liu

Published: 2019-06-07T00:00:00Z

Content type: tutorial

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [certificate](<https://devfeed.tech/tags/certificate.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [citadel](<https://devfeed.tech/tags/citadel.md>), [clusters](<https://devfeed.tech/tags/clusters.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [istio](<https://devfeed.tech/tags/istio.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [outage](<https://devfeed.tech/tags/outage.md>), [pki](<https://devfeed.tech/tags/pki.md>), [root](<https://devfeed.tech/tags/root.md>), [rotation](<https://devfeed.tech/tags/rotation.md>), [security](<https://devfeed.tech/tags/security.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

A guide to extending the lifetime of Istio self-signed root certificates and scheduling regular root transitions. It explains that the historical one-year lifetime can require annual rotation to prevent certificate expiration and potential cluster-wide outages.

### Source excerpt

Istio self-signed certificates have historically had a 1 year default lifetime. If you are using Istio self-signed certificates, you need to schedule regular root transitions before they expire. An expiration of a root certificate may lead to an unexpected cluster-wide outage. The issue affects new clusters created with versions up to 1.0.7 and 1.1.7. See Extending Self-Signed Certificate Lifetime for information on how to gauge the age of your certificates and how to perform rotation. We strongly recommend you rotate root keys and root certificates annually as a security best practice. We will send out instructions for root key/cert rotation soon.

## The Julia Community Prizes, 2018

DevFeed: [The Julia Community Prizes, 2018](<https://devfeed.tech/articles/the-julia-community-prizes-2018-46288.md>)

Original publisher: [Read original article](<https://julialang.org/blog/2018/09/julia-community-prizes/index.html>)

Author: Avik Sengupta

Published: 2018-09-04T00:00:00Z

Content type: news

Language: en

Sources: [JuliaLang - The Julia programming language](<https://devfeed.tech/sources/julialang-the-julia-programming-language.md>)

Topics: [The Julia Language](<https://devfeed.tech/topics/julia.md>), [Computing](<https://devfeed.tech/topics/computing.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [Development](<https://devfeed.tech/topics/development.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>)

Tags: [2018](<https://devfeed.tech/tags/2018.md>), [alan-edelman](<https://devfeed.tech/tags/alan-edelman.md>), [award](<https://devfeed.tech/tags/award.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [community](<https://devfeed.tech/tags/community.md>), [computing](<https://devfeed.tech/tags/computing.md>), [contributions](<https://devfeed.tech/tags/contributions.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [engagement](<https://devfeed.tech/tags/engagement.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [london](<https://devfeed.tech/tags/london.md>), [mit](<https://devfeed.tech/tags/mit.md>), [over](<https://devfeed.tech/tags/over.md>)

### AI overview

The Julia Community Prizes recognize four contributors for work extending Julia to GPUs, improving its test suite and documentation, developing JuliaDiffEq, engaging the community, and stewarding community infrastructure. The 2018 awards were announced at JuliaCon in London, with each recipient receiving a certificate and $1,000 prize.

### Source excerpt

The Julia Community Prizes, 2018 | The Julia Community Prizes celebrate the amazing set of scientists, developers and designers who have come together build such a strong and diverse ecosystem for numerical computing. Each of the four individuals chosen for the first award in 2018 have made immense contributions to Julia over many yea...