A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.
Jason Soroko
Jason Soroko is a seasoned security technology innovator and Senior Fellow at Sectigo, where he leads customer-facing engagements, drives research, and spearheads strategic initiatives at both organizational and national levels. He also contributes to the development of intellectual property and consortium standards. As co-host of the award-winning “Root Causes” podcast, Jason educates professionals on the latest trends in PKI and cybersecurity twice a week. His core strength is bridging cutting-edge security methods with real-world operational needs, ensuring that businesses are equipped with practical, forward-thinking solutions.
Recent posts by Jason Soroko
With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it.
Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments.
Because of a change in the drop-dead date, we have observed confusion about the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage. In this episode we spell out these dates very clearly.
In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.
In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication. In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.
MTCs reduce PQC overhead using compact proofs, enabling fast, transparent, and scalable post-quantum certificate authentication.
We survey different strategies for securely authenticating agentic AI, including certificates and SPIFFE. We discuss Zero Trust and the Principle of Least Privileges as applied to agents.
Anthropic has announced its intentions to support SPIFFE/SPIRE with the SPIRE server rooted in an "upstream authority," which will require a root private CA rather than allowing self-attestation for agentic AI.
