PKI News — certificate authority updates, TLS validity changes, browser root-program news

PKI News

Certificate authority actions, TLS updates, and FixMyCert analysis

A continuously maintained feed of certificate authority actions, TLS/SSL certificate-validity changes, browser root-program updates, and post-quantum developments — plus first-party FixMyCert analysis on what each change means for your infrastructure.

73

Articles

0

Sources

2

Priority Items

20

FixMyCert Analysis

An autonomous AI agent turned a single code-execution foothold into a network-wide breach by harvesting standing cloud and cluster credentials and moving laterally across internal clusters. The identity lesson is precise: short-lived, attested workload identities (SPIFFE/SPIRE) remove the static credential an attacker harvests and replays. They would not have stopped the break-in, but they would have contained it. Here is what workload identity would and would not have changed.

S/MIME BRs v1.0.15 also closes the issuance path for legacy intermediates: from September 15, 2027, CAs may not issue Subscriber certificates from any Subordinate CA whose RSA modulus is under 3072 bits. Certificates already issued are not revoked — renewals simply arrive under a different intermediate, which matters wherever that chain was pinned or manually installed. This is separate from the 2026 rule requiring newly created CA keys to be 4096-bit.

S/MIME BRs v1.0.15 (ballot SMC017v2, published July 30, 2026) raise the minimum RSA key size for Root and Subordinate CA certificates from 2048 to 4096 bits. The trigger is the key creation date, not certificate issuance — key material generated on or before September 15, 2026 remains usable under the 2048-bit minimum. Subscriber certificates are unaffected.

Our Sources