Loading
Loading
Expert analysis on PKI, post-quantum cryptography, and enterprise certificate operations.
A naive CBOM is worse than none: it gives the illusion of knowing. More than a list of algorithms: code, runtime and wire merged, alive, signed with ML-DSA-65. The real question is not which algorithms I have, but what I know, how certain I am, and whether it is still true right now.
ZetaCert Research
September 8, 2026

398 → 47 days by 2029: the bottleneck is DCV. The CA/B timeline, persistent validation with DNS-PERSIST-01, 6-day certificates, and multi-provider automation.
ZetaCert Research
July 11, 2026

Hybrid or composite? Two strategies to migrate your PKI to post-quantum without breaking existing clients. Comparison, sizes and a decision table.
ZetaCert Research
July 11, 2026

ANSSI recommends hybridizing classical and post-quantum mechanisms during the transition. Why pure ML-DSA falls short in regulated contexts, and what to do.
ZetaCert Research
July 11, 2026

AD CS now issues ML-DSA certificates. Actual scope, no hybrid mode, chains to re-sign, interop, HSMs: an analysis of the blind spots.
ZetaCert Research
July 11, 2026

Fourteen years after Heninger's audit of the Web PKI, we replayed the exercise. Here's what we found, and where the cryptographic risk has actually migrated.
ZetaCert Research
May 11, 2026
Technical analysis of the ESC vulnerabilities that turn ADCS into a privilege escalation vector. Every attack class from ESC1 to ESC13 explained.
ZetaCert Research
April 1, 2026
The post-quantum transition is not a theoretical topic. Standards are published, timelines are set. Is your PKI ready?
ZetaCert Research
April 1, 2026
Why the Active Directory PKI architecture no longer meets the demands of cloud, DevOps, and the post-quantum transition.
ZetaCert Research
March 4, 2026