With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it.
Resource Library
Because of a change in the drop-dead date, we have observed confusion about the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage. In this episode we spell out these dates very clearly.
MTCs reduce PQC overhead using compact proofs, enabling fast, transparent, and scalable post-quantum certificate authentication.
A digital signature is a secure way to verify who signed an electronic document and to confirm that the contents have not been altered. Built on public key infrastructure (PKI), it uses...
Private PKI powers machine identity management by automating certificates, improving security, and preventing outages at scale.
Legacy PKI implementations hold back technical progress and create security risk. We discuss reasons why, consequences, and what to do about it.
SSH keys not only improve security but also enable the automation of connected processes, single sign-on (SSO), and identity and access management at scale that today’s businesses require.
Sectigo Blog
The PKI perfect storm: how to kill three birds with one stone (spoiler: the stone is automation)
47-day certs, post-quantum cryptography (PQC), and mutual TLS (mTLS) deadlines are colliding. Automation is the one stone that solves them all.
We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates. You can find this research at https://orbilu.uni.lu/handle/10993/66334.
The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.
Chain of lure is an attack method used to circumvent restrictions and boundaries placed on AIs. Jason explains this attack and its implications.
NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC. We explain this code-based algorithm.
We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.
We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems.
Need assistance?
Contact our team for help with your purchase or issuing your certificate.