Creating Highly Available CDP and AIA Locations with Azure, Part 4

Hello everyone, this is the fourth blog post in my “Creating Highly Available CDP and AIA Locations with Azure” series. Posts in this series: Part 1 Part 2 Part 3 Part 4 (this post) In this blog post, we will configure an on-premises environment to upload CA certificates and CRLs to a primary Azure storage […]

Creating Highly Available CDP and AIA Locations with Azure, Part 3

Hello everyone, this is the third entry in my “Creating highly available CDP and AIA locations with Azure” series. Posts in this series: Part 1 Part 2 Part 3 (this post) Part 4 Deploying Azure Front Door CDN Resource As we already discussed, Azure Front Door (AFD) is: A modern cloud Content Delivery Network (CDN) […]

Creating Highly Available CDP and AIA Locations with Azure, Part 2

Hello everyone, this is the second entry in my “Creating highly available CDP and AIA locations with Azure” series. Posts in this series: Part 1 Part 2 (this post) Part 3 Part 4 Start Environment In my previous post, I provided a setup configuration for us to start from: Fig.1 – Initial Setup We have […]

Creating Highly Available CDP and AIA Locations with Azure, Part 1

Hello everyone, this is the first blog post in the “Creating Highly Available CDP and AIA Locations with Azure” series. Posts in this series: Part 1 (this post) Part 2 Part 3 Part 4 Foreword With the fast TLS expansion over the last decade, PKIs and their administrators face new challenges in order to provide […]

To Revoke or Not to Revoke: Balancing Security with Performance and Operational Complexity

As a PKI engineer, I have consistently faced the challenges associated with certificate revocation. In several positions, I’ve been tasked with implementing automation to perform certificate revocation in bulk. Although I appreciated a task that showcased my coding skills, I often argued against such processes. I believe that many organizations misunderstand certificate revocation and how […]

Goodbye MD5 – Sooner Than You Think!

If you recall, last year Microsoft took a small step to increase the security of enterprises by following industry standards that weaker/shorter keylengths were no longer viable for production use. Microsoft did this with KB 2661254 which prevented Windows operating systems from validating certificates with key lengths shorter than 1024. Recently, Microsoft announced Security Advisory 2862973 that will block […]

The PKI Guy drills down on PKI operations with Jeff Stapleton, author

Q&A with J.J. Stapleton, co-author of Security without Obscurity: A Guide to PKI Operations TPG: What practical advice do you have for an organization considering deploying a PKI solution? JS: There are various PKI architectures to consider. An internal private PKI deployed wholly within the organization, a hosted private PKI deployed at a third-party service provider, or […]