Revisiting BetterTLS: Certificate Path Building

8 · Netflix, Inc. · Oct. 14, 2021, 7:01 p.m.
By Ian HakenLast year the AddTrust root certificate expired and lots of clients had a bad time. Some Roku devices weren’t working right, Heroku had problems, and some folks couldn’t even curl. In the aftermath Ryan Sleevi wrote a really great blog post not just about the issue of this one certificate’s expiry, but the problem that so many TLS implementations have in general with certificate path building. If you haven’t read that blog post, you should. This post is probably going to make a lot m...