<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Tls on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/tls/</link>
    <description>Recent content in Tls on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Tue, 15 Sep 2026 09:30:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/tls/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Webex Is Looking For Your Certificates On A Cisco Build Server</title>
      <link>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</link>
      <pubDate>Tue, 15 Sep 2026 09:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</guid>
      <description>Webex on Linux says &amp;#34;Offline - No internet connection&amp;#34; on a machine whose network is fine: the OpenSSL Cisco ship looks for its trust store inside their own build container. What breaks, the fixes that fail, the one that works, what the build process got wrong, and how a security appliance vendor ships a client that cannot check a certificate.</description>
    </item>
    <item>
      <title>A VPN Out of Parts: PPP, Tap Devices and Netcat</title>
      <link>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</link>
      <pubDate>Mon, 14 Sep 2026 15:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</guid>
      <description>A VPN is a virtual link plus a carrier, and Linux ships a program for each: pppd or a tap device, and netcat. Building it both ways — over TCP, UDP, TLS and DTLS, with zstd compression — shows what a VPN is made of, and what egress really is: once an attacker has root and outbound is open, the tunnel is already installed.</description>
    </item>
    <item>
      <title>A VM&#39;s Clock Cannot Be Trusted — and the ptp_kvm Fix for QEMU/KVM</title>
      <link>https://blogs.damiendye.uk/en/proxmox/vm-time-ptp-kvm/</link>
      <pubDate>Fri, 07 Aug 2026 13:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/vm-time-ptp-kvm/</guid>
      <description>A virtual machine&amp;#39;s clock is built on an assumption virtualisation breaks: that the CPU keeps counting. Why guest time drifts on every hypervisor, what the skew actually breaks — Kerberos, TLS, Ceph, Windows — and how ptp_kvm fixes it properly on QEMU/KVM.</description>
    </item>
  </channel>
</rss>
