Certificates

CA/Browser Forum: ACME CAA Extensions (RFC 8657) To Become Mandatory

May 14, 20265 min read

The CA/Browser Forum has spoken: ACME CAA extensions will be mandatory from March 2027 onward.

Read more
Certificates

High-Assurance Certificate Transparency Monitoring with Red Sift Certificates

May 1, 20266 min read

Learn how to detect unauthorized certificate issuances with Certificate Transparency monitoring. Set up CAA policies, CT monitoring rules, and high-assurance escalation in Red Sift Certificates.

Read more
Certificates

Should you use public PKIs for your private infrastructure?

Apr 30, 20265 min read

Public PKIs are cost-effective for internal use, but come with trade-offs like certificate transparency, rate limits, and shrinking lifetimes. Here's how to decide between public and private PKI.

Read more
Certificates

How many public PKIs are there?

Apr 30, 20265 min read

Public Key Infrastructures go far beyond Web PKI. Explore the full landscape of public PKIs — from code signing and S/MIME to BIMI and Matter — and learn which one fits your needs.

Read more
Certificates

PKI ecosystem changes in 2026: what your team needs to know

Mar 19, 20267 min read

2026 brings shorter certificate lifetimes, unmanaged private PKI, and looming post-quantum migration. A concise guide to the changes security teams need to plan for.

Read more
Certificates

How expired certificates can cause service downtime and financial losses

Jan 21, 20263 min read

Certificate expiry outages cost enterprises up to $5 million per incident and take hours to resolve. This post covers the financial impact and how to prevent them.

Read more
Certificates

Towards monthly certificate renewal

Jan 13, 20268 min read

Certificate lifetimes are shrinking to 47 days by 2029. This post explains why shorter lifetimes improve security and why automation is now essential for renewal.

Read more
Certificates

Certificate Lifecycle Management needs a dedicated monitoring platform

Jan 13, 20265 min read

CLM tools manage issuance and renewal, but dedicated monitoring platforms provide the real-time discovery and Certificate Transparency visibility that enterprises actually need.

Read more
Certificates

Cryptographic discovery requires deep infrastructure expertise and big data

Jan 13, 20264 min read

Ivan Ristic explains how building a cryptographic discovery platform requires combining deep network infrastructure knowledge with large-scale monitoring of domains, DNS, and certificates.

Read more
Certificates

Certificate Transparency should be the key aspect of your cryptographic discovery strategy

Jan 13, 20264 min read

Certificate Transparency logs provide real-time visibility into every certificate issued for your domains. This post explains why CT should anchor your cryptographic discovery strategy.

Read more
Certificates

Certificate Monitoring versus Certificate Lifecycle Management

Nov 11, 20258 min read

CLM automates the certificate lifecycle from issuance to expiry, while certificate monitoring focuses on discovery and visibility. This post explains when you need each — and why you likely need both.

Read more
Certificates

How to build an inventory of certificates for PCI DSS 4.0 Requirement 4.2.1.1

Nov 11, 20258 min read

PCI DSS 4.0 Requirement 4.2.1.1 mandates a complete certificate inventory by March 2025. This guide walks through how to build and maintain one using automated discovery.

Read more
Certificates

TLS Certificate Lifetimes Are Shrinking: What's Changing

Apr 24, 20255 min readFrancesca Rünger-Field

Certificate authorities are moving toward shorter TLS lifetimes. Here's what the changes mean for your renewal process and how to stay ahead.

Read more
Certificates

Six-Day TLS Certificates: What You Need to Know

Jan 28, 20254 min readFrancesca Rünger-Field

Proposals for six-day certificate lifetimes would require near-continuous automation. Here's what's being proposed, why, and how to prepare.

Read more
Certificates

PCI-DSS Takes Aim at Phishing: What It Means for Compliance

Jan 22, 20254 min readBilly McDiarmid

The latest PCI-DSS update puts phishing prevention in scope. Here's what changed, what's required, and how to get ahead of the requirements.

Read more
Certificates

Apple and Chrome Propose Shorter Certificate Lifetimes

Oct 22, 20243 min readJack Lilley

Apple and Chrome are backing proposals to reduce TLS certificate validity periods. Here's what shorter lifetimes mean for your PKI operations.

Read more
Certificates

PCI DSS 4.0 Cryptographic Requirements: A Practical Guide

Aug 27, 20246 min readRebecca Warren

PCI DSS 4.0 tightens the rules on cryptography and certificate management. Here's what's required, what's changed, and how to become compliant.

Read more
Certificates

Google Distrusts Entrust Certificates: What to Do Now

Jul 2, 20244 min readRed Sift

Google Chrome will stop trusting Entrust-issued certificates from October 2024. Here's what's affected, the timeline, and how to reissue safely.

Read more
Certificates

Why Certificate Transparency Logs Are Your Best PKI Defence

Dec 20, 20236 min readIvan Ristic

CT logs give you visibility into every certificate issued for your domains — including ones you didn't authorise. Here's how to use them proactively.

Read more
Certificates

How HTTPS Replaced HTTP — and Why It Still Matters

Jul 26, 20183 min readRed Sift

HTTPS is now the baseline for web security, but many organisations still have gaps. Here's how the transition happened and what to watch for now.

Read more