EXPLORE RESOURCES

SSL/TLS Articles

7 Articles

Public-Facing Router Certificate Hardening Techniques

Having a properly issued, correctly chained certificate on a public-facing router, covered in the general best practices article earlier in this series, is the starting point, not the finish line. Hardening goes further, actively reducing the attack surface around that certificate and the TLS configuration surrounding it. This article focuses specifically on hardening techniques that go beyond basic certificate hygiene.

Load Balancer Certificate Updates Without Service Interruption

Several earlier articles in this series covered load balancer certificate best practices for specific platforms, HAProxy, NGINX, F5 BIG-IP. This article steps back to focus specifically on the general mechanics of updating a certificate on any load balancer without dropping a single active connection, a discipline that applies across virtually every load balancing technology regardless of vendor.

Load Balancer Certificate Best Practices for HAProxy and NGINX

HAProxy and NGINX power a substantial share of the world\’s load balancing and reverse proxy infrastructure, and both handle TLS termination with their own specific configuration conventions and quirks. This article covers practical certificate best practices for each, building on the broader load balancer SSL termination concepts covered elsewhere in this series.

Certificate Pinning for IoT and Mobile Applications

Standard certificate validation trusts any certificate that chains back to a recognized root, which works well for the open web but leaves a gap for applications that connect to one specific, known backend and want to trust nothing else, even a technically valid certificate from a compromised or coerced CA. Certificate pinning closes that gap. This article covers how pinning works, where it genuinely helps, and the operational risks it introduces if handled carelessly.

Securing MQTT and CoAP with Machine Certificates

MQTT and CoAP are the two lightweight protocols most commonly powering IoT and constrained-device communication, chosen specifically because they minimize overhead on devices with limited processing power and unreliable connectivity. Securing them properly with certificates requires understanding how each protocol handles TLS differently from the standard web traffic most certificate discussions focus on. This article covers exactly that.

Load Balancer SSL Termination: Certificates Done Right

Load balancers occupy a unique position in most modern application architectures: they are frequently the single place where encrypted traffic from the outside world gets decrypted before being distributed to backend servers. That makes their certificate configuration disproportionately important. Get it wrong, and every application behind the load balancer inherits the weakness. This article covers what SSL termination at the load balancer actually involves and the practices that keep it secure.

Buying SSL/TLS Certificates: Best Practices for 2026

The rules governing SSL and TLS certificates have shifted meaningfully over the past few years, and 2026 is shaping up to be a pivotal year for anyone still treating certificate purchasing as a once-a-year, set-it-and-forget-it task. This article covers what organizations should actually be doing when buying certificates today, with an eye toward the shorter lifespans, tighter automation requirements, and expanding machine identity needs that now define the landscape.