A digital signature is a secure way to verify who signed an electronic document and to confirm that the contents have not been altered. Built on public key infrastructure (PKI), it uses...
Resource Library
Private PKI powers machine identity management by automating certificates, improving security, and preventing outages at scale.
Legacy PKI implementations hold back technical progress and create security risk. We discuss reasons why, consequences, and what to do about it.
SSH keys not only improve security but also enable the automation of connected processes, single sign-on (SSO), and identity and access management at scale that today’s businesses require.
Sectigo Blog
The PKI perfect storm: how to kill three birds with one stone (spoiler: the stone is automation)
47-day certs, post-quantum cryptography (PQC), and mutual TLS (mTLS) deadlines are colliding. Automation is the one stone that solves them all.
We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates. You can find this research at https://orbilu.uni.lu/handle/10993/66334.
The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.
Chain of lure is an attack method used to circumvent restrictions and boundaries placed on AIs. Jason explains this attack and its implications.
NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC. We explain this code-based algorithm.
We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.
We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems.
We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.
Public CAs will drop TLS client auth by February 2027. Switch to private CA and CLM now to secure VPNs, Wi-Fi, mTLS, and device identity workflows.
Need assistance?
Contact our team for help with your purchase or issuing your certificate.