Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your chained cert might actually be the bottleneck if the total data exceeds 4K and the user has to do a second round trip to ACK the cert.

http://journal.paul.querna.org/articles/2010/07/10/overclock...

Basically, unless you are certain you need it 4096 bit security, use a 2048 bit key (1024 is not secure anymore) and only include the minimum number of intermediate certs you can get away with. OSCP stapling doesn't seem worth it if it cause you to over flow the initial TCP window.



this is a really great piece of advice. i'll check this out.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: