< ciso
brief />
Tag Banner

All news with #pki tag

21 articles

DNS Root KSK-2024 Rollover and Readiness Test

πŸ” On October 11, 2026 the DNS root will replace its key-signing key (KSK) with KSK-2024 (key tag 38696). Most site operators need take no action, but operators of DNSSEC-validating resolvers must ensure their trust anchors include KSK-2024 before the switch to avoid service outages. Cloudflare’s resolvers already include the new key and offer a RFC 8509-based readiness test at dnstest.dev to check whether the resolver your browser uses trusts the new root key. The post explains KSK vs ZSK roles, RFC 5011 automatic updates, and why embedding the new anchor in resolver software helps avoid issues seen during the 2018 rollover.
read more β†’

AWS Private CA connectors arrive in GovCloud

πŸ”’ AWS Private Certificate Authority (AWS Private CA) now offers the AWS Private CA Connector for Kubernetes as a managed Amazon EKS add-on and the AWS Private CA Connector for Active Directory in AWS GovCloud (US-East) and (US-West). These additions simplify certificate automation for government workloads, integrating with cert-manager to provision and renew TLS certificates in Kubernetes and enabling AD-based automatic issuance for domain-joined objects. The service secures private keys using FIPS 140-3 Level 3 HSMs.
read more β†’

Amazon API Gateway adds mutual TLS for backends

πŸ” You can now configure Amazon API Gateway REST APIs to present an AWS Certificate Manager (ACM) certificate to your backend during the TLS handshake, enabling mutual TLS (mTLS). Previously API Gateway only offered a self-signed certificate; now you may use certificates from your trusted certificate authority or issue/manage them via AWS Private Certificate Authority. Certificate updates in ACM propagate automatically with no redeployments.
read more β†’

Google donates ZKP library to Linux Foundation Europe

πŸ”’ Google has donated its Longfellow Zero-Knowledge Proof (ZKP) library, open-sourced last year, to the Post-Quantum Cryptography Alliance under Linux Foundation Europe. This transfer establishes vendor-neutral, open stewardship to enable global trust, auditability, and adoption as a quantum-safe standard for digital identity applications. Google will continue developing and supporting the library openly and collaborating with experts worldwide to scale interoperable digital credential solutions across devices and browsers.
read more β†’

ACM Adds ACME Support to Automate TLS Certificates

πŸ”’ This post announces ACME protocol support in AWS Certificate Manager (ACM), enabling customers to use familiar ACME clients like certbot and cert-manager to automate public certificate issuance and renewal. It explains the new ACME endpoint resource, domain validation scopes, EAB credentials, and IAM controls for isolating environments. The article outlines setup steps, operational best practices, and monitoring recommendations to help scale certificate automation securely.
read more β†’

Proof‑of‑Concept for Certighost AD CS Exploit

πŸ”’ A proof-of-concept exploit for the β€œCertighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS β€œchase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more β†’

AWS Certificate Manager adds managed ACME endpoints

πŸ›‘οΈ AWS Certificate Manager (ACM) now offers a fully managed ACME server endpoint that issues public TLS certificates with 45-day validity from Amazon Trust Services, compatible with any ACMEv2 client such as Certbot, cert-manager, and acme.sh. PKI teams can create managed ACME endpoints with domain scopes, wildcard controls, and delegated issuance without sharing DNS credentials. Domain validation is performed once at the endpoint level, and issuance and renewal activities are auditable via the ACM console, AWS CloudTrail, and Amazon CloudWatch. ACME support is available in all commercial AWS Regions; see ACM pricing and documentation for details.
read more β†’

Researchers Find RSA Keys Containing Large Zero Blocks

πŸ” New research identifies a class of weak RSA keys characterized by extensive zeroed blocks in the modulus. The open-source badkeys project collected large-scale key material from CT logs, TLS/SSH scans, and PGP repositories and found multiple real-world keys exhibiting two distinct sparse patterns. Pattern 1 appeared in certificates (now expired) from major organizations and devices, while Pattern 2 appeared in SSH hosts using CompleteFTP; affected versions and time ranges are noted. The findings highlight independent cryptographic implementations failing in similar ways and raise concerns about deliberate backdoors or coordinated vulnerabilities.
read more β†’

CloudFront Adds OCSP Revocation Checking for mTLS Support

πŸ” Amazon CloudFront now supports Online Certificate Status Protocol (OCSP) for viewer mutual TLS (mTLS), allowing real-time validation of client certificate revocation during connection establishment. Previously, revocation was handled via CloudFront Functions and KeyValueStore with static lists. CloudFront now queries the OCSP responder embedded in certificates and caches responses up to 30 minutes. The OCSP result is exposed to connection functions for custom logic.
read more β†’

AWS Payment Cryptography: Physical Key Exchange Support

πŸ” AWS Payment Cryptography now offers Physical Key Exchange, a PCI PIN and P2PE-compliant option that enables paper-based cryptographic key exchange without customers having to maintain their own secure key-loading infrastructure. Paper key components are shipped to trained AWS key custodians, who perform key ceremonies in AWS-operated secure facilities meeting the required physical and logical controls. Once loaded, keys are available to the managed service for cryptographic operations, helping organizations accelerate migration when partners do not support electronic key exchange.
read more β†’

Cryptographic Reset: Operational Shifts in Trust Now

πŸ” The cryptographic foundation of the internet is undergoing a rapid operational reset driven by shorter certificate lifecycles and the transition to quantum-resistant algorithms. The CA/Browser Forum reduced public TLS validity to 200 days on March 15, 2026, with further reductions planned to 100 days in 2027 and 47 days by 2029, dramatically increasing renewal velocity. Manual certificate processes and spreadsheets will not scale; organizations need network-native discovery, continuous certificate visibility, and fully automated lifecycle management. Palo Alto Networks' Next-Generation Trust Security brings certificate lifecycle controls into the network to automate discovery, renewal, deployment and governance.
read more β†’

Cloudflare Radar: origin PQ, Key Transparency, ASPA

πŸ” Cloudflare Radar is adding three security-focused datasets and tools: origin-facing post-quantum (PQ) monitoring, a Key Transparency dashboard for E2EE messaging logs, and enhanced RPKI ASPA adoption tracking. The origin feature reports support for X25519MLKEM768 using an automated TLS scanner and provides an on-demand hostname tester that performs real TLS handshakes via Cloudflare Containers. Key Transparency publishes auditor verification status and APIs for independent proof checks, while routing pages gain global, country, and per-AS ASPA views together with API access for integrations.
read more β†’

ASPA Deployment and Roadmap for More Secure Routing

πŸ”’ ASPA (Autonomous System Provider Authorization) introduces cryptographic path validation to reduce route leaks by allowing networks to publish signed lists of authorized upstream providers in RPKI. Unlike ROAs, which verify prefix origins, ASPA validates the AS_PATH and detects routing "valleys" that indicate leaks. Cloudflare Radar now tracks ASPA adoption across RIRs and provides per‑AS visibility so operators can see whether observed upstreams are ASPA‑authorized and monitor changes over time.
read more β†’

HTTPS Certificate Industry Phases Out Weak Domain Checks

πŸ”’ The Chrome Root Program and the CA/Browser Forum have adopted new requirements (Ballots SC-080, SC-090, and SC-091) to phase out 11 legacy Domain Control Validation methods. These deprecated checks β€” including email, fax, SMS, postal mail, phone-based contacts, and reverse lookup methods β€” are being retired to reduce the risk of fraudulent certificate issuance. The policies update the TLS Baseline Requirements and encourage stronger, automated, cryptographically verifiable methods such as ACME, with full security value realized by March 2028 while operators transition.
read more β†’

AWS Private CA Adds Partitioned CRLs for Scale, Compliance

πŸ”’ AWS Private Certificate Authority now supports partitioned Certificate Revocation Lists (CRLs) to scale revocation handling up to 100 million certificates per CA. Partitioning breaks revocation data into ~1 MB CRL partitions and binds certificates to partitions using a critical Issuer Distribution Point (IDP) extension, allowing validators to match CDP and IDP URIs for accurate checks. The feature is backward compatible, RFC5280-compliant, configurable in the console (including S3 setup), and carries no charge beyond AWS Private CA and Amazon S3 usage.
read more β†’

AWS Private CA Adds ML-DSA Post-Quantum Certificates

πŸ” AWS Private CA now supports the post-quantum digital signature algorithm ML-DSA (NIST FIPS 204), enabling organizations to create CAs and issue certificates designed to resist quantum attacks. The feature lets you test certificate issuance, identity verification, and code signing using ML-DSA, and supports CRLs and OCSP responders. Availability spans all commercial AWS Regions, AWS GovCloud (US), and China Regions to help teams begin transitioning PKI toward post-quantum cryptography.
read more β†’

Google Cloud's Roadmap to a Quantum-Safe Infrastructure

πŸ”’ Google Cloud has been migrating its infrastructure toward post-quantum cryptography for nearly a decade to mitigate Store Now, Decrypt Later (SNDL) risks. The company has deployed the standards-based ML-KEM (FIPS 203) for key exchange across internal traffic and the Google Cloud networking stack, and introduced ML-KEM capabilities in Cloud KMS (preview) for key generation, encapsulation, and decapsulation. It also added native support for ML-DSA and SLH-DSA in Cloud KMS to protect long-lived digital signatures, and is phasing quantum-safe certificate support into Certificate Authority Service to enable future PQC-ready PKI. Administrators will receive tooling to opt in, audit cryptographic assets, and manage transitions to hybrid or pure PQC deployments as standards mature.
read more β†’

Merkle Tree Certificates pilot by Cloudflare and Chrome

πŸ” Cloudflare is collaborating with Chrome to experimentally deploy Merkle Tree Certificates (MTCs) to reduce the number of public keys and large post-quantum signatures transmitted during TLS handshakes. MTCs batch certificates into a Merkle tree with a single signed treehead and per-certificate inclusion proofs, dramatically shrinking handshake size and CPU work. The experiment will roll out to a subset of Cloudflare free customers while Chrome distributes validation landmarks and fallbacks to preserve existing trust.
read more β†’

Microsoft October Windows Updates Break Smart Card Auth

πŸ”’ Microsoft warns the October 2025 Windows security updates are causing smart card authentication and certificate failures by switching RSA-based smart card certificates to use KSP instead of CSP. Affected systems may report errors such as "invalid provider type specified" or "CryptAcquireCertificatePrivateKey error" and Event ID 624 in the Smart Card Service log. Microsoft provides a manual workaround: set the DisableCapiOverrideForRSA registry value to 0, back up the registry first, then restart. This impacts Windows 10, Windows 11 and Windows Server releases; the company says the key will be removed in April 2026 and urges customers to work with application vendors to resolve compatibility.
read more β†’

Transitioning to Passwordless Authentication with PKI

πŸ” Organizations facing rising phishing and ransomware threats are moving from passwords to PKI-based authentication to close gaps in traditional MFA. Certificates issued by a trusted CA and backed by asymmetric cryptography replace passwords and vulnerable SMS codes, improving both security and usability. Automated lifecycle management and user self-service reduce administrative overhead, while crypto-agility preserves long-term resilience.
read more β†’