<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>TLS on Aperture Zone</title>
    <link>https://aperturezone.com/tags/tls/</link>
    <description>Recent content in TLS on Aperture Zone</description>
    <image>
      <url>https://aperturezone.com/logo.webp</url>
      <link>https://aperturezone.com/logo.webp</link>
    </image>
    <generator>Hugo -- gohugo.io</generator>
    <language>fr-fr</language>
    <lastBuildDate>Mon, 24 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aperturezone.com/tags/tls/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Layers 5 and 6: The Phantom Layers</title>
      <link>https://aperturezone.com/osi/5-6/</link>
      <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      
      <guid>https://aperturezone.com/osi/5-6/</guid>
      <description>&lt;p&gt;Fifth and sixth layers. After the &lt;a href=&#34;https://aperturezone.com/osi/rj45/&#34;&gt;cable&lt;/a&gt;, the &lt;a href=&#34;https://aperturezone.com/osi/mac-addresses/&#34;&gt;MAC addresses&lt;/a&gt;, the &lt;a href=&#34;https://aperturezone.com/osi/IP/&#34;&gt;IP&lt;/a&gt;, and &lt;a href=&#34;https://aperturezone.com/osi/TCP/&#34;&gt;TCP&lt;/a&gt;, logically, we should be talking about the session layer, followed by the presentation layer.&lt;/p&gt;
&lt;p&gt;Except that we have to be honest: &lt;strong&gt;these two layers are practically nonexistent.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Not in the sense that they’re useless—but in the sense that, in the network you manage every day, &lt;strong&gt;no one implements them as such&lt;/strong&gt;. There is no “Layer 6 protocol” the way there is a Layer 3 (IP) or Layer 4 (TCP). These are two layers that the OSI model envisaged, that theory describes in detail, and that reality has simply absorbed elsewhere.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>Layer 7: The Application — HTTP, DNS, DHCP, and the Top of the Stack</title>
      <link>https://aperturezone.com/osi/application/</link>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      
      <guid>https://aperturezone.com/osi/application/</guid>
      <description>&lt;p&gt;Seventh and final layer. We started with the &lt;a href=&#34;https://aperturezone.com/osi/rj45/&#34;&gt;cable&lt;/a&gt;, we went through &lt;a href=&#34;https://aperturezone.com/osi/mac-addresses/&#34;&gt;MAC addresses&lt;/a&gt;, &lt;a href=&#34;https://aperturezone.com/osi/IP/&#34;&gt;IP and routing&lt;/a&gt;, &lt;a href=&#34;https://aperturezone.com/osi/TCP/&#34;&gt;TCP and ports&lt;/a&gt;, and we found that &lt;a href=&#34;https://aperturezone.com/osi/layers-5-6-ghosts/&#34;&gt;layers 5 and 6 were phantom layers&lt;/a&gt;. Here we are at the top.&lt;/p&gt;
&lt;p&gt;And the top is where everyone lives. Layer 7 is what you see: the browser loading a page, an email being sent, a domain name being resolved, the machine receiving its IP address at startup. This is the &lt;strong&gt;application&lt;/strong&gt; layer—the only one the user interacts with directly, and by far the richest in protocols.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>From a Homemade PKI to Step-CA: Moving Away from Manual Signatures (Part 1)</title>
      <link>https://aperturezone.com/posts/pki1/</link>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      
      <guid>https://aperturezone.com/posts/pki1/</guid>
      <description>Pendant lontgemp, ma PKI interne a reposé sur une autorité de certification OpenSSL pilotée à la main : une racine, des certificats de deux ans signés un par un. Ça marchait — jusqu&amp;#39;à ce que le nombre de services rende le modèle intenable. Cette première partie raconte la bascule vers step-ca : comment réutiliser la racine existante pour ne pas casser la confiance déjà déployée, comment passer à des certificats courts renouvelés automatiquement, et comment industrialiser le motif sur toute la flotte sans transformer chaque machine en corvée.</description>
    </item>
    
  </channel>
</rss>
