TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
6 to work through
-
intermediate
A partner reports your API fails from their servers with a certificate error. It works in every browser you try and from your laptop. Diagnose and prevent.
1 min answer -
intermediate
A production outage was caused by an expired internal certificate. Nobody was tracking it. Design the fix.
2 min answer -
intermediate
An internal service-to-service certificate expires at 02:00 on a Sunday. What is the impact and what should have prevented it?
2 min answer -
intermediate
Ballot SC-081v3 cut the maximum public TLS certificate lifetime to 200 days from 15 March 2026, with 100 days from March 2027 and 47 days from March 2029. A team currently renews its 400 public certificates by quarterly ticket. What does the shorter ceiling buy, and what is the bill?
2 min answer -
intermediate
Where should TLS terminate in a platform serving customer traffic, and what changes when a compliance requirement demands encryption in transit inside the network?
2 min answer -
advanced
A commerce platform hosts storefronts on hundreds of thousands of merchant-owned custom domains, each needing a valid certificate. What architecture handles certificate issuance, renewal and termination at that scale?
3 min answer
5 terms in this topic
Certificate Chain
The sequence from a server's certificate through one or more intermediate CAs to a root the client already trusts.
practiceCertificate Lifecycle Management
Issuing, deploying, monitoring and renewing certificates automatically, because manual tracking reliably produces outages.
protocolMutual TLS
TLS in which both ends present certificates, so the server authenticates the client cryptographically rather than by a shared secret.
protocolServer Name Indication
The cleartext hostname a client sends in its first TLS message, letting one address serve many certificates and letting a proxy route a session befor…
practiceTrust Boundary Classification
Writing down which network segments count as trust boundaries, so that mutual TLS is applied where it changes the security posture rather than unifor…
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.