Daniel Rehak
Contributor to the My-SSL learning library. The articles below cover code signing, certificate standards and implementation topics and are attributed to Daniel in the library’s bylines.
Editorial information and correctionsArticles by Daniel
- Can You Sign a Docker Image With a Code Signing Certificate?
- How to Sign RPM and DEB Packages (and Why a Code Signing Certificate Won't)
- NuGet Trusted Signers: Fixing NU3034 After a Certificate Rotation
- Why Malware Gets Signed With Valid Certificates
- Code Signing Key Attestation: Using Your Own HSM
- FIPS 140-2 Is Historical: What It Means for Code Signing
- ACME Certificate Profiles: Which One to Ask For, and What Breaks
- Certificate Problem Reports: Who Can Start Your Revocation Clock
- Certificate Linting: The Check That Runs Before a Certificate Is Signed
- Authorization Domain Names: Which Name Your CA Actually Validates
- CAA Account Binding: What accounturi and validationmethods Do
- ACME Renewal Information (ARI): Letting the CA Set Your Renewal Window
- Authority Information Access: What the AIA Extension Must Actually Contain
- S/MIME Certificate Key Sizes: What Changed on September 15, 2026
- Code Signing Certificates Must Now Carry a Reserved Policy OID
- EV Domain Validation Reuse: The 398-Day Number Is Gone
- NIS2 and Certificates: What the Directive Actually Requires of Your Encryption
- Android Code Signing: Why There Is No Certificate to Buy, and What Developer Verification Changes
- Secure Boot Certificate Expiration: What Changed in June, What Happens on October 19
- Post-Quantum Code Signing: What You Can Actually Buy in 2026
- Did AI Break AES? What Claude's HAWK and 7-Round AES Results Actually Mean
- Java Keytool Commands Cheat Sheet: Keystore, CSR, Import and Trust
- Shor's Algorithm Explained: How It Breaks RSA and ECC