Solved

Reducing the size of certificate chain

Posted on 2016-10-05
2
41 Views
Last Modified: 2016-10-14
HI,
Following is a capture of wireshark :
 Screen-Shot-2016-10-05-at-5.22.43-PM.pngHere there are 3 certificates and the size is : 4310 bytes
Here are the certificates as i see in chrome :

Screen-Shot-2016-10-05-at-5.22.54-PM.png
I read up the following rule for optimization of certificates :
Ideally, your sent certificate chain should contain exactly two certificates and A carefully managed certificate chain can be as low as 2 or 3 KB in size

But the certificate chain for my site exceeds 4 KB.
Please suggest any approach to lower this down.. I think i will have to somehow get away with the intermediate certificate..

Thanks
0
Comment
Question by:Rohit Bajaj
2 Comments
 
LVL 14

Assisted Solution

by:Schnell Solutions
Schnell Solutions earned 150 total points
ID: 41829973
If that is the chain of one specific certificate you cannot change it. What you can do is to use a 'different' certificate that uses a shorter chain. However, it means re-issue a new certificate and complete the entire process to implement the new one.

On another hand you will not wish to set one intermediate certificate as a root ca to shorten the path in your server as far as it would be a very bad security practice.
0
 
LVL 23

Accepted Solution

by:
Dirk Kotte earned 350 total points
ID: 41830172
your book are from 2013. Last years we double the certificate length and nearly every CA add some sub-CAs.
The statement: "which will overflow the initial congestion windows size of older servers ..." is not current.

Using a certificate with fewer intermediate chains and / or a smaller public key size can reduce the amount of data but is not an option today ...mostly...
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now