With certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again. We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is generally a bad policy.
Ressourcen
X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates. We clarify why this is not the case.
"Chaos engineering" describes the practice of injecting faults into a system to see what happens. This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.
Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results. As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results. This ultimately can result in completely unusable information.
It is possible to use common tools like OpenSSL to create your own ML-DSA private CA. This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.
We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.
Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.
There is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be.
Sectigo Blog
So unterschreiben Sie ein PDF: Erläuterung der Methoden für elektronische und digitale Signaturen
Eine PDF-Datei ist eine beliebte digitale Ressource für offizielle Dokumente: Verträge, Geschäftsvereinbarungen, juristische Dokumente und sogar Personalformulare. Die Abkürzung steht für „Portable Document Format“; dieses Dateiformat wurde von...
It is surprising that we continue to see root expirations occur at the most inopportune times. Weekends, public holidays, even New Year's Eve. In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."
SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.
With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it.
Sectigo Orchestration Gateway (SOG) ist eine schlanke Lösung für den Sectigo Certificate Manager (SCM), die die Verwaltung von TLS-Zertifikaten vereinfacht. Sie ersetzt komplexe Skripte und Konnektoren durch ein einziges Gateway und bietet eine durchgängige Automatisierung von der Erkennung bis zur Erneuerung. SOG sichert den Zugriff durch Just-in-Time-Abruf von Anmeldedaten (PAM) und bereitet Unternehmen auf kürzere Zertifikatslaufzeiten und postquantenkryptografische Verfahren vor.
Erfahren Sie, wie SOG mit SCM zusammenarbeitet, um eine sichere, skalierbare und richtliniengesteuerte Zertifikatsautomatisierung zu ermöglichen.
Erfahren Sie, wie SOG den SCM erweitert, um den Lebenszyklus von TLS-Zertifikaten in komplexen Hybrid- und Multi-Cloud-Umgebungen zu automatisieren.
Sectigo Blog
Skalierung des Zertifikatslebenszyklusmanagements (CLM) mit dem Sectigo Orchestration Gateway (SOG)
Das Sectigo Orchestration Gateway (SOG) vereinheitlicht die Zertifikatsautomatisierung und ersetzt Skripte und Konnektoren durch eine skalierbare, sichere Lebenszyklus-Orchestrierung.
Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments.
A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.
Benötigen Sie Hilfe?
Benötigen Sie Hilfe beim Kauf? Kontaktieren Sie uns noch heute, um Ihr Zertifikat sofort zu erhalten.