We define a new term, Quantum Security Posture Management (QSPM) and explain what it is and why it's important for PQC plans.
Ressources
Gérez et automatisez tous vos certificats (eIDAS QWAC, PSD2 QWAC, SSL/TLS) sur une plateforme unique pour garantir la continuité de vos activités.
SCM centralise et automatise la gestion des certificats eIDAS QWAC et PSD2 QWAC sur une seule console aux côtés de vos certificats SSL/TLS.
Sectigo Blog
Sectigo Quantum Ready<sup style="font-size: 0.3em; vertical-align: super; top: -0.5em;">™</sup>: passer de la prise de conscience quantique à l'action quantique
Sectigo Quantum Ready™ aide les entreprises à identifier leurs vulnérabilités cryptographiques et à jeter les bases d’une préparation post-quantique et d’une agilité cryptographique.
In this first of two episodes, we discuss the expected scientific applications for quantum computing architecture and the idea of a Scientifically Relevant Quantum Computer (SRQC).
Les options de tenancy flexibles de la plateforme Sectigo Partner Platform aident les partenaires à adapter la gestion des certificats aux différents besoins des clients grâce à des environnements dédiés ou partagés sécurisés.
Quantum Key Distribution (QKD) is supposed to be this highly secure method of key exchange. But is it as secure as people say? We explore the potential weaknesses with QKD.
We follow up on the recent Mythos attack against PQC candidate HAWK. We discuss the impact of this attack on both HAWK and FALCON.
TLS certificates from CA/Browser Forum CAs are not the only server certificates in the WebPKI. eIDAS QWACs are treated as server certificates by the major browsers. We see clear progress toward post quantum cryptography (PQC) for TLS by way of the Merkle Tree Certificate (MTC) architecture. But what is the path to PQC for eIDAS? We examine this question.
Automatisez le déploiement des certificats sur F5 Distributed Cloud grâce à Sectigo Orchestration Gateway et réduisez les risques liés aux renouvellements à grande échelle.
As certificate lifespans become extremely short, new methods of delivery become functionally necessary. We explain RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates.
With certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again. We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is generally a bad policy.
X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates. We clarify why this is not the case.
"Chaos engineering" describes the practice of injecting faults into a system to see what happens. This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.
Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results. As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results. This ultimately can result in completely unusable information.
It is possible to use common tools like OpenSSL to create your own ML-DSA private CA. This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.
We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.
Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.
Besoin d'aide ?
Besoin d'aide pour effectuer un achat ? Contactez-nous dès aujourd'hui pour que votre certificat soit délivré immédiatement.