< ciso
brief />
Tag Banner

All news with #certificate management tag

44 articles

Edge PQC Growth Masks Broader Quantum Readiness Gaps

🔒 F5 Labs finds 54% of the top 1M websites now support post-quantum key exchange, but much of that progress stems from CDNs enabling PQC rather than enterprises upgrading their own infrastructure. The study examined only front-end connections and did not assess origin servers, internal APIs, or service-to-service links, leaving many internal attack paths exposed. Experts urge organizations to inventory cryptographic dependencies, prioritize long-term confidential data, and adopt hybrid PQC and automated certificate management to achieve true readiness.
read more →

ACM Adds PrivateLink for ACME Certificate Issuance

🔒 AWS Certificate Manager (ACM) now supports AWS PrivateLink for ACME public certificate issuance, enabling requests and renewals over a private network path within the AWS network. You can create a VPC interface endpoint to the ACM ACME service and route issuance traffic from any ACMEv2-compatible client through your VPC. Existing ACME clients require no configuration changes because Private DNS resolves the same ACME directory URL to the interface endpoint internally. Issuance operations and monitoring remain available via the ACM console, AWS CloudTrail, and Amazon CloudWatch.
read more →

AWS Private CA adds detailed issuance logs

📜 The new AWS Private CA CloudTrail IssueCertificateDetails event records full certificate content, issuing CA data, requester identity, and signing status for every issuance. It captures the complete TBS certificate with X.509 fields and convenience fields like subject, issuer, serial, validity, template, and algorithm. Events include both successful and failed issuances and identify the requester (account/IAM principal or service principal). Delivered automatically as a CloudTrail management event in supported Regions, it can be consumed in real time via EventBridge or queried with Athena at standard CloudTrail cost.
read more →

Cloudflare announces PQ-capable CA using MTCs

🔐 Cloudflare outlines its plan to operate a post‑quantum capable Certificate Authority (CA) that supports Merkle Tree Certificates (MTCs) to enable scalable, efficient PQ authentication. The post explains how MTCs integrate issuance and transparency, reducing the cost of PQ signatures and improving auditability with cosigners and mirrors. Cloudflare will offer MTC issuance for free, build ACME tooling, and target Chrome inclusion in early 2027.
read more →

Cloudflare announces intent to become a public CA

🔒 Cloudflare today announced its intent to become a public certificate authority (CA), detailing milestones including applications to major root programs and an agreement to acquire a trusted root from GlobalSign. The company plans ACME-first automation, support for post-quantum and Merkle Tree Certificates, and transparency through reproducible builds and public dashboards. Cloudflare emphasizes reliability, redundancy, and gradual adoption while continuing partnerships with existing CAs.
read more →

AWS Private CA connectors arrive in GovCloud

🔒 AWS Private Certificate Authority (AWS Private CA) now offers the AWS Private CA Connector for Kubernetes as a managed Amazon EKS add-on and the AWS Private CA Connector for Active Directory in AWS GovCloud (US-East) and (US-West). These additions simplify certificate automation for government workloads, integrating with cert-manager to provision and renew TLS certificates in Kubernetes and enabling AD-based automatic issuance for domain-joined objects. The service secures private keys using FIPS 140-3 Level 3 HSMs.
read more →

Amazon API Gateway adds mutual TLS for backends

🔐 You can now configure Amazon API Gateway REST APIs to present an AWS Certificate Manager (ACM) certificate to your backend during the TLS handshake, enabling mutual TLS (mTLS). Previously API Gateway only offered a self-signed certificate; now you may use certificates from your trusted certificate authority or issue/manage them via AWS Private Certificate Authority. Certificate updates in ACM propagate automatically with no redeployments.
read more →

Equifax adopts AI to modernize cybersecurity

🔒 Equifax is combating evolving threats by combining strengthened cybersecurity hygiene with AI-driven automation across operations and development. EVP and CISO Jeremy Koppen highlights a 30% rise in attacks driven by automation and a shrinking window to patch vulnerabilities. Equifax has rolled out passwordless access for partners, a business exposure map, automated certificate management, and AI-assisted code review that reduced review time from 46 to 18 days.
read more →

Amazon EKS adds automated CA rotation lifecycle

🔐 Amazon Elastic Kubernetes Service (Amazon EKS) now supports managed certificate authority (CA) rotation with automated safeguards. Amazon EKS will manage the rotation lifecycle and update AWS-managed components to trust the successor CA, while customers must replace worker nodes and update external clients to trust the new CA. Features include advance expiration notifications, automatic successor CA appending and activation, and rollback capability. The feature is available at no additional cost in all commercial AWS Regions and can be managed via CLI, APIs, CloudFormation, and the AWS console.
read more →

AWS to End Email Validation for ACM Certificates

🛡️ AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027, aligning with the CA/B Forum’s March 15, 2028 deprecation of email-based domain validation. Customers must migrate to DNS validation; ACM is updating the UpdateCertificateOptions API to allow in-place switching from email to DNS without changing certificate ARNs. ACM provides a CNAME record for DNS validation and offers a 72-hour window to add it; once validated, ACM will handle automatic renewals. AWS provides console and AWS CLI steps, a migration user guide, and support resources to assist customers through the transition.
read more →

ACM lets you switch validation from email to DNS

🔐 AWS Certificate Manager now allows changing domain validation on existing public TLS certificates from e-mail to DNS without reissuing or changing the ARN. ACM will phase out email validation through 2027 per CA/B Forum mandates; it will stop issuing email-validated certs on March 31, 2027 and stop renewing them on September 30, 2027. Use the console or UpdateCertificateOptions API to switch and add provided CNAME records within 72 hours.
read more →

Cloudflare reduces noise in CT monitoring alerts

🛡️ Certificate Transparency Monitoring, launched in public beta in 2019, now filters out certificates Cloudflare issues on customers' behalf before sending alerts. This change addresses noisy notifications caused by routine Universal SSL renewals and other Cloudflare-managed certificates. The service is generally available and will only notify customers about certificates issued outside Cloudflare's automated systems. Settings remain available in the Cloudflare dashboard.
read more →

Mozilla revokes Linux signing subkey after exposure

🔐 Mozilla revoked the OpenPGP subkey used to sign Firefox and Thunderbird Linux downloads after an unencrypted copy was mistakenly committed to a private repository. The revocation means files signed by the old subkey will stop verifying once users import the revocation; most users are unaffected, but manual verifiers and some RPM-based installs must update keys. A new replacement subkey was published with a 2028 expiry, and Mozilla says audit logs show no evidence of external access despite the revocation reason code indicating compromise.
read more →

ACM Adds ACME Support to Automate TLS Certificates

🔒 This post announces ACME protocol support in AWS Certificate Manager (ACM), enabling customers to use familiar ACME clients like certbot and cert-manager to automate public certificate issuance and renewal. It explains the new ACME endpoint resource, domain validation scopes, EAB credentials, and IAM controls for isolating environments. The article outlines setup steps, operational best practices, and monitoring recommendations to help scale certificate automation securely.
read more →

Proof‑of‑Concept for Certighost AD CS Exploit

🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more →

AWS Certificate Manager adds managed ACME endpoints

🛡️ AWS Certificate Manager (ACM) now offers a fully managed ACME server endpoint that issues public TLS certificates with 45-day validity from Amazon Trust Services, compatible with any ACMEv2 client such as Certbot, cert-manager, and acme.sh. PKI teams can create managed ACME endpoints with domain scopes, wildcard controls, and delegated issuance without sharing DNS credentials. Domain validation is performed once at the endpoint level, and issuance and renewal activities are auditable via the ACM console, AWS CloudTrail, and Amazon CloudWatch. ACME support is available in all commercial AWS Regions; see ACM pricing and documentation for details.
read more →

Governing the growing ghost workforce risk

🛡️ Enterprises are facing an invisible workforce: non-human identities (bots, service accounts, API keys, tokens, certificates) that now often outnumber humans. These ghost identities authenticate constantly across environments and, when unmanaged, accumulate privileges and risks. The industry has seen incidents where forgotten or third-party machine identities enabled widespread breaches, and a looming 2026 certificate-expiration wave threatens cascading outages. Organisations must prioritise governance—discovering NHIs, assigning ownership, auditing privileges, and addressing imminent certificate expirations—before tool selection.
read more →

AWS launches Workload Credentials Provider for certs

🔒 AWS announced the AWS Workload Credentials Provider, a lightweight client-side tool that automates export and deployment of certificates from AWS Certificate Manager and local caching of secrets from AWS Secrets Manager. It removes the need for custom EventBridge-based automation for certificate renewals, supports Windows and Linux, and works with Apache and NGINX. The provider is open source and compatible with Secrets Manager Agent functionality.
read more →

CloudFront Adds OCSP Revocation Checking for mTLS Support

🔐 Amazon CloudFront now supports Online Certificate Status Protocol (OCSP) for viewer mutual TLS (mTLS), allowing real-time validation of client certificate revocation during connection establishment. Previously, revocation was handled via CloudFront Functions and KeyValueStore with static lists. CloudFront now queries the OCSP responder embedded in certificates and caches responses up to 30 minutes. The OCSP result is exposed to connection functions for custom logic.
read more →

Amazon CloudFront Adds mTLS Passthrough Mode for Origins

🔐Amazon CloudFront now supports passthrough mode for viewer mutual TLS (mTLS), enabling customers to forward client certificate chains directly to their origin for validation instead of requiring CloudFront to perform certificate verification. In passthrough mode CloudFront forwards every request and the full client certificate chain to the origin and does not cache responses, ensuring end-to-end authentication is enforced by the origin. Connection functions remain available so you can inspect or transform connection-level data before it reaches your origin. CloudFront mutual TLS (viewer) passthrough is available at no additional cost.
read more →