PKI can fail operationally while cryptography is sound
Almost every real certificate failure is a process failure, not a mathematical one.
An expired certificate nobody renewed. A key on a laptop that left with an employee. A revocation nobody checks. An internal authority whose backup was never tested. The algorithms perform exactly as designed throughout. This is the same pattern as key management generally: the maths holds and the administration around it does not.
More on TLS and PKI
- TLS encrypts a connection, not endpoint intentionsA sealed pipe to a stranger
- Certificates bind keys to names through trust chainsHeld together by a chain of seals
- Certificate expiry creates operational pressureEvery one of them runs out
- Private-key compromise survives a valid certificateThe certificate is fine
- HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit tooThe turning that stops existing
- OCSP stapling moves status evidence closerThe proof comes stapled on
