The Role of PKI and Certificate Lifecycle Management in API Security
Krupa Patil | | API security, API sprawl, Certificate Authorities (CA), CLM automation solution, Identity and Access Management (IAM), Kubernetes, Public Key Infrastructure (PKI)
Imagine booking a flight online. You check airline schedules, compare ticket prices, reserve seats, and make payments—all on a single website. This seamless experience is made possible by the power of APIs (Application Programming Interfaces) that enable different applications, like the airline’s booking system, payment gateways, and our email provider, ... Read More
Agent vs Agentless: Which Deployment to Choose for Certificate Lifecycle Management
Krupa Patil | | certificate lifecycle management, IoT devices, PKI, private keys, Privileged Access Management (PAM), SSH
When implementing a certificate lifecycle management (CLM) solution in an organization, the choice between agent-based and agentless architectures is an important decision that can significantly impact the deployment, operations, and scalability of the solution. If you’re unsure which approach aligns with your organization’s needs, this guide breaks down the key ... Read More
Certificate Management Best Practices to Stay Cyber-Secure This Holiday Season
Krupa Patil | | certificate authority, Certificate Lifecycle Automation, Certificate Management, CLM practices, hardware security module (HSM), Role Based Access Control (RBAC), TLS certificate lifespans
The holiday season is in full swing, and for retailers and e-commerce businesses, it is one of the busiest times of the year. As festive shopping picks up and customers flock online to snag the best deals, online traffic surges to record-breaking levels. Online retail spending is expected to hit ... Read More
Apple’s Revised Proposal for 47-Day TLS Certificate Lifespans
Krupa Patil | | 47 days tls certificate, Apple's 47 days certificate lifespans, certificate lifecycle management, PKI, Post-Quantum Cryptography, TLS certificate lifespan
Apple’s recent proposal to slash public TLS certificate lifespans from 398 days to 45 days had sparked intense discussions in the PKI community. Introduced in a recent CA/Browser (CA/B) Forum meeting, the draft ballot presented by Apple proposed a gradual reduction of the maximum validity for public SSL/TLS certificates from ... Read More
A Closer Look at NIST’s Legacy Encryption Algorithm Transition Plans and Finalized PQC Algorithm Standards
Krupa Patil | | certificate lifecycle management, digital signature algorithm, NIST, PKI hierarchy, Post-quantum cryptography (PQC), PQC readiness, public-key cryptographic algorithms
NIST sets key deadlines for retiring legacy encryption algorithms, with widely-used methods like RSA, ECDSA, EdDSA, DH, and ECDH set for deprecation by 2030 and full phase-out by 2035. Last week, NIST released an Initial Public Draft (IPD) report outlining its recommended roadmap for transitioning from traditional public-key cryptographic algorithms ... Read More

PKI and CLM Insights from 2024: Preparing for a Cyber Resilient 2025
Krupa Patil | | certificate lifecycle management (CLM), CLM solution, Kubernetes, PKI, PKI as a Service (PKIaaS), Post-quantum cryptography (PQC), PQC certificates, SSL/TLS Certificates
As the year winds down, it’s the perfect time to pause for retrospection. 2024 has been both exciting and challenging for the PKI and CLM space, pushing the industry to rethink strategies and adapt. From the explosive growth of non-human and machine identities to the proposed move toward shorter-lived certificates ... Read More
Why PKIaaS is a Smarter and Secure Alternative to On-Premises PKI
Krupa Patil | | Certificate Lifecycle Management (CLM) Automation, cloud based pki, PKI infrastructure, PKI management, pkiaas, private pki, private trust use cases, public certificates
Private PKI (Public Key Infrastructure) is critical for trusted authentication and secure communication among internal applications, devices, workloads, machines, and services. While most organizations understand its importance, managing it effectively is still a struggle for many. Traditionally, organizations manage private PKI on-premises for greater control, security, and customization. However, as ... Read More

The Entrust Distrust Deadline is Closing In. Are you Prepared?
Krupa Patil | | certificate lifecycle management solution, Certificate Management, crypto-agility, entrust ca, Entrust distrust, Entrust Migration, PKI, Public CA
We’re just weeks away from November 12, 2024—the date when Google Chrome will begin distrusting newly issued certificates from Entrust Roots. Shortly after, Mozilla will implement its distrust in Entrust Roots by the end of November. If your organization hasn’t yet switched to a reliable public Certificate Authorities (CA), it’s ... Read More
Apple Follows Google’s Lead: Get Ready for 45-Day TLS Certificate Lifespans
Krupa Patil | | CA/Browser (CA/B) Forum, certificate lifecycle management, certificates and keys, crypto-agility, shorter certificate lifespans, SSL/TLS Certificates
At the last CA/Browser (CA/B) Forum meeting, Apple dropped a big announcement, causing quite a stir in the PKI industry. Apple introduced a draft ballot, proposing a gradual reduction of the maximum validity for public SSL/TLS certificates from 398 days to just 45 days by 2027. The proposal also includes ... Read More
Don’t Let an Expired Certificate Cause Critical Downtime. Prevent Outages with a Smart CLM
Krupa Patil | | certificate authorities, certificate lifecycle management, Certificate Outages, Certificate Signing Request, CLM tools, digital certificates, expired certificate, machine identity management, Smart CLM, TLS certificate
If there’s one thing Microsoft, Spotify, Google Voice, and the Bank of England have in common, what would it be? All of them have recently been rocked by a major outage caused by an expired TLS certificate that significantly disrupted their operations and essential public services. The ripple effect of ... Read More