An Explainer Guide on Multi-Perspective Issuance Corroboration (MPIC)
Starting Sept 15, 2025, all publicly trusted certification authorities (CAs such as DigiCert, Sectigo, etc.) must perform domain validation and CAA record checks using multiple network perspectives. This method, known as multi-perspective issuance corroboration (MPIC), aims to ensure that an attacker who poisons or compromises DNS servers in one area won’t be able to issue an SSL/TLS or S/MIME certificate for a domain they don’t control.
This concept of MPIC is similar to how the National Hockey League (NHL) relies on multiple officials (two referees, 2 linesmen) during a hockey game:
Seeing as how this next phase of the certificate issuance requirement rollout takes effect next week, and we’ve not talked much about MPIC before, now seems like the perfect time to briefly talk about what MPIC entails for websites and email. We’ll also address why these changes are happening and how this multiple vantage point verification approach improves security by mitigating fraudulent server certificate issuances.
Let’s hash it out.
The post An Explainer Guide on Multi-Perspective Issuance Corroboration (MPIC) appeared first on Hashed Out by The SSL Store™.
The Python Package Index (PyPI) now rejects new files being uploaded to releases that are…
Over the next few months, we will be rolling out changes to the PyPI user…
Highlighting the next stage in our sidebar reorganization campaign! We are still primarily focusing on…
Source: SMS Email Gateway ID Provider Country Email Format Notes Id Provider Country Email Address…
In 2023 PyPI completed its first security audit, and I am proud to announce that…
This post will drill deeper into two recent supply chain exploits, targeting users of popular…
This website uses cookies.