tls
Safeguard articles tagged "tls" — guides, analysis, and best practices for software supply chain and application security.
36 articles
Perfect forward secrecy
Perfect forward secrecy stops a single leaked TLS key from unlocking years of past traffic. Here's how ephemeral key exchange works, and why it matters for supply chain security.
Envoy Proxy Security Hardening for Production Deployments
Envoy powers service meshes and API gateways across the industry. Its default configuration prioritizes connectivity over security. Here is how to fix that.
Symmetric vs Asymmetric Encryption, Explained
What makes an encryption algorithm symmetric is a single shared key for both encryption and decryption; asymmetric algorithms use a mathematically linked public/private key pair instead — and the difference decides which one you should reach for.
MCP Transport Layer Security Options
MCP supports stdio, streamable HTTP, and a handful of experimental transports. Each has distinct security properties, and the choice of transport constrains every other security decision you make about the deployment.
Certificate Pinning for Software Updates: When and How to Pin
Certificate pinning can protect your update channel from MITM attacks, but it introduces operational complexity. Here is when pinning makes sense and how to do it safely.
Kubernetes Ingress Security Configuration: Getting It Right
Ingress controllers are the front door to your Kubernetes cluster. Misconfigurations here expose everything behind them.
CVE-2025-15467 in OpenSSL CMS: Patch Posture & SBOM Response
OpenSSL CMS pre-auth stack buffer overflow scored CVSS 9.8. Mail servers, web servers, and anything that processes S/MIME need the fix. Defender playbook below.
TLS Library Comparison: OpenSSL vs BoringSSL vs LibreSSL vs rustls
Your TLS library choice has massive security implications. Here is an honest comparison of the major options and what each trade-off means.
NGINX Security Configuration Guide for Production Deployments
NGINX powers a third of the internet. Its default configuration is optimized for getting started, not for production security. Here is the gap.
TLS Configuration Security Audit: What to Check and How
A misconfigured TLS setup can be worse than no encryption at all because it creates false confidence. Here is how to audit your TLS configuration properly.
Certificate Authority Compromise and Supply Chain Risks
A compromised certificate authority can undermine TLS trust for your entire software supply chain. Understanding CA risks is essential for defending package integrity and secure distribution.
Heartbleed at Five Years: A Practitioner Retrospective
Five years after CVE-2014-0160, Heartbleed still shapes how we think about shared cryptographic libraries, disclosure ethics, and open-source funding.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.