r/PKI Aug 23 '23

/r/PKI - Policy changes and new mod

5 Upvotes

Hello everyone,

I am the new mod of /r/PKI as the previous mod had gone inactive and was not able to respond to requests to maintain their mod status of the sub.

Feedback and requests can be submitted to this thread.

Changes to the sub and moderation strategy are currently as follows:

August 23rd 2023 - Sub no longer restricted to approved posters only, open submission is enabled.

October 10th 2025 - Added basic post flair options (Question/News/Misc.) + started assigning custom flair to community members that have been particularly helpful or noteworthy.

April 28th 2026 - Comments in response to requests for help that are asks to move to private forms of communication rather than explore the problem in the thread will be removed.

August 19th 2026 - Companies looking to advertise their products/webinars are limited to no more than one advertising post a month. If a post is functionally identical to a previous post it will be removed.


r/PKI 3h ago

Should machine trust-store distribution be part of certificate lifecycle management?

2 Upvotes

We've been working on certificate lifecycle automation, and one problem we've recently moved into is CA trust distribution.

Issuing and renewing certificates is one side of PKI operations, but eventually there are environments where you also need to establish or remove trust across machines.

We just added a model where an operator can approve CA material and distribute it through an outbound-only agent to machine trust stores on:

  • Windows
  • Debian/Ubuntu
  • RHEL/Fedora

A few safety properties we decided on:

  • the CA certificate fingerprint is pinned before distribution
  • the agent re-verifies the fingerprint before touching the trust store
  • we track whether the certificate was installed by the control plane or was already present
  • removal is only allowed for material the agent can prove it installed
  • multiple references to the same CA are reference-counted, so removing one reference doesn't remove trust another workload still depends on
  • retiring an anchor stops new distributions but does not automatically fan out removals
  • trust changes create audit/evidence records

One thing we're deliberately not trying to encourage is installing intermediates as a workaround for servers that don't present a proper chain. That's a different problem.

What we're debating is the architectural boundary.

For those operating private PKI at scale, do you consider machine trust distribution part of CLM/PKI lifecycle management, or should the PKI system stop at defining the desired trust state and leave deployment entirely to tools like GPO, Intune, Ansible, Puppet ?

And if you do automate trust-store changes, what safeguards do you consider mandatory before you'd let the system remove a CA ?

The CertOps implementation of Tokentimer is open source if anyone wants to inspect or use it : https://github.com/tokentimerch/tokentimer-core


r/PKI 4d ago

802.1X WPA3 Authentication on Windows 11: User and Machine Authentication

Post image
11 Upvotes

I'm configuring 802.1X for certificate-based authentication at my enterprise. Windows 11 is causing me some difficulty, and I'm not sure what to do here.

The objective:

  • At the Windows pre-logon screen, I want the wireless network to authenticate using the Machine Certificate in the Machine store.
  • When a user logs in, I want the wireless network to authenticate using the User Certificate in the User store.

A wireless network can be configured to authenticate using "User or Computer Authentication" for this exact behaviour.

The problem

  • When the wireless profile is set to "Computer authentication", the wireless network successfully authenticates using the machine certificate in both the pre-logon environment, as well as after a user logs into the machine.
  • When the wireless profile is set to "User authentication", the wireless network successfully authenticates using the user certificate after a user logs in.
  • When the wireless profile is set to "User or computer authentication", the wireless network is able to authenticate when a user is logged in.
    • When the computer is at the pre-logon environment, the following error message is displayed:

Unable to connect because you need a certificate to sign in. Contact your IT support person.

The Event Viewer shows the following:

Wireless 802.1x authentication failed.
Adapter: Intel(R) Wi-Fi 6E AX211 160MHz Network
Interface GUID: {fa945db8-64a4-4c3d-b0be-1dada024320e}
Local MAC Address: {{ My MAC address }}
Network SSID: {{ My SSID }}
BSS Type: Infrastructure
Identity: NULL
User: SYSTEM
Domain: NT AUTHORITY
Reason: Explicit Eap failure received
Error: 0x80420014
EAP Reason: 0x80420100
EAP Root cause String: Network authentication failed\nThe user certificate required for the network can't be found on this computer.
EAP Error: 0x80420014

This almost sounds as though the Windows pre-logon environment isn't looking in the Machine store during the authentication attempt to this wireless network. It says "The user certificate required[...]", which makes it sound like it's trying to find a user certificate for an environment that is inaccessible within the pre-logon environment.

Question: Does anyone here have experience in configuring 802.1x with both machine and user certificate authentication?

Edit: The answer is TEAP! Tunneled EAP is exactly what I was trying to achieve. Cheers u/lazyjk and u/cormacolinde


r/PKI 6d ago

Getting Let’s Encrypt Certificates using RFC2136 on Technitium DNS server Fails

2 Upvotes

I have public facing Technetium DNS servers resolving hosts. The zones are setup and configured to use Dynamic Updates. Reference:- https://blog.technitium.com/2023/03/how-to-auto-renew-ssl-certificates-with.html

However, it is failing with the following error “ Certbot.errors: Unable to determine base domain for _acme-challenge.<sebat7.com> using names: \[‘_acme-challenge.sebat7.com’ , ‘sebat7.com’ , ‘com’\]

Unable to determine base domain for _acme-challenge.sebat7.com using names : \[‘_acme-challenge.sebat7.com’ , ‘sebat7.com’ , ‘com’\]

I tried Certbot and also Nginx Proxy Manager with the RFC2136 plugins. I need help nor don’t mind paying a consultant to resolve this imperative issue. Any help or recommendation of a consultant will be much appreciated. Thank you.


r/PKI 6d ago

Getting Let’s Encrypt Certificates using RFC2136 on Technitium DNS server Fails

Thumbnail
0 Upvotes

r/PKI 6d ago

Getting Let’s Encrypt Certificates using RFC2136 on Technitium DNS server Fails

0 Upvotes

I have public facing Technetium DNS servers resolving hosts. The zones are setup and configured to use Dynamic Updates. Reference:- https://blog.technitium.com/2023/03/how-to-auto-renew-ssl-certificates-with.html

However, it is failing with the following error “ Certbot.errors: Unable to determine base domain for _acme-challenge.<sebat7.com> using names: \[‘_acme-challenge.sebat7.com’ , ‘sebat7.com’ , ‘com’\]

Unable to determine base domain for _acme-challenge.sebat7.com using names : \[‘_acme-challenge.sebat7.com’ , ‘sebat7.com’ , ‘com’\]

I tried Certbot and also Nginx Proxy Manager with the RFC2136 plugins. I need help nor don’t mind paying a consultant to resolve this imperative issue. Any help or recommendation of a consultant will be much appreciated. Thank you.


r/PKI 8d ago

Free live event this Thursday: PKI from a CISO’s perspective

Post image
5 Upvotes

Hey all, we’re hosting another free live event this Thursday and thought some of you here might be interested.

This time we’re talking with cybersecurity executive John Shaffer about PKI from the CISO side of things. We’ll get into how security leaders think about PKI risk, resilience, and modernization, especially in highly regulated environments. We’ll also talk about what organizations are actually doing right now to prepare for post-quantum cryptography.

It’s a 45-minute conversation and we’ll have time for questions.

Thursday, August 27 at 10 a.m. PT

Free to attend if you want to join us: Register Here


r/PKI 8d ago

Somebody's been keeping a list of your certificates

Thumbnail
certkit.io
4 Upvotes

Wrote up a self-audit of our own CT log footprint.

Browsers do not look a certificate up in a log at connection time. They verify SCTs, the log's signed promise to publish, embedded in the cert. No network call. Whether the log kept that promise is audited after the fact.

So a cert can be trusted and not yet findable in a CT search.

https://www.certkit.io/blog/somebody-is-keeping-a-list-of-your-certificates


r/PKI 11d ago

Do companies actually private/inhouse ACME services?

4 Upvotes

Is there a market for this. I have a codesigning/document server product, which also has it's own internal CA for internal certificates - I was thinking about adding an acme server to it, but not sure there is even a market for it. What do people use for internal servers - how are they provisioning/renewing TLS certificates?


r/PKI 11d ago

"crypto agility" sounds like it’s simply an abstract notion. A term that we will later come to despise.

3 Upvotes

Crypto agility seems good on the surface. Avoid hard coding any algorithms. Instead, establish a unified policy. However I have witnessed too many infrastructure abstractions turn into indispensable dependencies. Moving to PQC from PKI/Crypto where the first option involves requiring every application to support new crypto for a long period of time or implementing an abstraction layer, which will make switching crypto independent of the application.

It will be faster for legacy systems if we implement the second option. The first option looks clearer after ten years. I'm eager to learn which of the two options specialists who have worked with PKI systems would choose.


r/PKI 11d ago

AWS ACM ACME certs are 45 days now. What still breaks after issuance is automated?

4 Upvotes

AWS ACM's ACME certificates are 45 days, and renewal is handled by the ACME client.

That's probably a decent preview of where public TLS operations are heading anyway.

What interests me more is what happens after the client gets the replacement certificate.

For nginx or something with native ACME integration, fine. But plenty of infrastructure still needs another step. Import a PFX. Update a keystore. Push the cert to an appliance. Change a listener binding. Reload a service. Sometimes reboot the thing.

And "certificate issued successfully" doesn't tell you whether the endpoint is actually serving it.

I've started thinking about certificate automation as separate states:

issued
installed
activated
verified on the live endpoint

The last two seem to be where a lot of supposedly automated setups can still quietly fail.

For people running ACME at scale, what systems are still giving you trouble after issuance itself is automated?


r/PKI 14d ago

CertPing: unified certificate lifecycle and trust-surface management

Thumbnail
0 Upvotes

r/PKI 17d ago

Cache max-age and CRLDP

6 Upvotes

Apparently if your CRLDP end point doesn't set max-age in the response header browsers may use a heuristic method to guesstimate how long to cache it, like (current date - last modified date) / 10. What this means practically is that if say your root CA CRL is refreshed once a year, if a client happens to download it at the wrong time, the browser will consider the cached file to be fresh even if current date is past the NextUpdate date set on the CRL (and remember Chromium browsers don't use CAPI2 to handle CRLs anymore).

So basically in addition to the intended RFC5280 mechanisms for determining when to refresh the cached CRL, it's also subject to browser-side rules on how long to cache files, since CRLs are handled like any other downloaded content under Chromium.


r/PKI 20d ago

What are the hardest problems in PQC migration after crypto discovery?

Thumbnail
6 Upvotes

r/PKI 24d ago

Checkpoint Endpoint Security on Mac with CardOS 5.3 PKI smart card certificate

2 Upvotes

Hello,

I just switched from Windows and I would like to setup the Checkpoint Endpoint Security (latest version) on MacOS, but it doesn't recognize my smart card in the list.

The smart card is a PKCS#15 Atos CardOS 5.3 with an USB Gemalto Reader. The certificate is on the smart card, it's not possible to export, it should be used from the card with a pin code.

MacOS doesn't see the card or the certificates "security list-smartcard" and other commands says No smartcards found, however, I download OpenSC and with that everything is visible, the card, the reader and all certificates on the card.

I downloaded many smart card tools as well and only the Personal Nexus software is able to recognize the card and the certificates, but on the checkpoint the list is empty. I installed also the latest version of Gemalto SafeNet Authentication Client (SAC) which also didn't recognize the card.

On Windows we used CSP+ software for the card/certificate recognition, but that's not available on mac and besides mac handles card totally differently.

Please help me to find a solution for this problem.

Many thanks,


r/PKI 26d ago

Can I install a second Enterprise CA on a new server in an existing 2-DC/1-CA environment (Server 2025)?

3 Upvotes

I have a new environment with 2 DCs (Server 2025). One of the DCs already has the Enterprise CA role installed. My question: is it possible to install a second, separate Enterprise CA role on another new server?


r/PKI 26d ago

Sectigo Certificate Manager

5 Upvotes

Any SCM users here? We've recently implemented SCM and looking for other peers to share experiences with. :-)


r/PKI 27d ago

PKI/PAM/SSO job in Germany

6 Upvotes

Is there any English-speaking PAM, SSO, or PKI job in Germany? I’ve been trying for quite some time, but the market seems quite dry at the moment


r/PKI 27d ago

Signotaur 2.1: Self hosted Code and Document Signing Server

Thumbnail
finalbuilder.com
3 Upvotes

New Release of Signotaur - Document Signing (pdf, xml and others) with PAdES, XAdES and CAdES signature formats.

Signotaur is a Code Signing/Document Signing server - your private keys never leave the server (or the token/hsm attached to it).


r/PKI 28d ago

Free text vs. standardized algorithm registries in CBOMs—what are people using?

2 Upvotes

I've been thinking about cryptographic inventories and CBOMs recently, and one question keeps coming up.

When recording cryptographic assets, is free text still sufficient for things like algorithms, curves, and key types, or should inventories move toward standardized registries and controlled values?

For example, "RSA-2048", "rsa2048", and "RSA 2048" all describe the same thing, but inconsistent naming makes discovery, reporting, compliance, and eventually post-quantum migration more difficult.

At the same time, adopting a controlled registry introduces more structure and governance, so there are tradeoffs.

For those building or consuming CBOMs, PKI inventories, or cryptographic discovery tools:

  • Are standardized algorithm registries becoming a requirement?
  • Or is free text still good enough in practice?
  • What additional metadata do you consider essential beyond the algorithm itself (ownership, provenance, first/last seen, confidence, etc.)?

We've been exploring these kinds of challenges in the open-source ILM (Identity Lifecycle Management) community, particularly around maintaining accurate cryptographic inventories as environments continuously change. I'm curious how others are approaching this and where you see the industry heading.


r/PKI Aug 02 '26

AD-PKI: An open-source, self-hosted CA with ACME, OCSP and RFC 3161 — looking for technical feedback

7 Upvotes

Hi everyone,

I’m the developer of AD-PKI, an open-source and self-hosted platform for operating an internal public key infrastructure.

I started building it because I wanted a manageable internal certificate authority with modern certificate automation, without relying entirely on a commercial PKI product or issuing and renewing certificates manually.

The project currently includes:

  • ACME v2 for automated certificate enrollment and renewal
  • OCSP and certificate revocation lists
  • RFC 3161 timestamping
  • A web-based administration interface
  • Role-based access control
  • Certificate templates and policy management
  • Separation between the management backend and the CA service

A central design decision is the separation of the management components from the dedicated CA service. The frontend and backend handle administration, policies and certificate metadata, while private CA key operations are intended to remain inside the CA component.

Website and documentation:

https://adpki.de/

Source code:

https://github.com/alid-it/AD-PKI

The project is still young and has not undergone an independent security audit. I’m therefore particularly interested in critical technical feedback rather than just promotion.

I would appreciate feedback on:

  • The separation between the backend and CA service
  • Private-key handling and security boundaries
  • ACME compatibility and expected challenge types
  • OCSP and CRL implementation requirements
  • Root and intermediate CA workflows
  • HSM or PKCS#11 integration expectations
  • Features needed for realistic production use
  • Documentation or architectural decisions that are unclear

This is my own project. It is open source and self-hosted.

Thanks for taking a look.


r/PKI Jul 30 '26

How’s business?

8 Upvotes

TLDR: I’m already balls deep running CAs at home and practicing migrations between technologies, I am genuinely interested in PKI. How do you find this as a specialism. Does it pay well and are there regular gigs?

Hello Enterprise Trust Specialists.

Im currently an IT security Consultant in the softest sense, I’m an infrastructure generalist but ultimately an ambulance chaser (Vulnerability Management).

I pitch myself and am very often the SME within IAM but the kind of firms I contract in and out of want surface level stuff. My British friends will be familiar with the softball CE+ which basically consists of making sure your shit is up to date.

Enough with the preamble, I genuinely love AuthN / AuthZ generally in the IAM space which as I’m sure you’re very much aware is basically just a strategic grouping exercise.

I have been angling towards and practicing the discipline of PKI for quite a while, I’ve done a couple of full migrations and several hardening projects - typically less than 3000 certs and low stakes because really nobody cares. Currently wholly ADCS + Intune.

I feel like PKI in some ways is the purest form of authentication and I think it’s going to become or already is / should be a top agenda item as more and more businesses move to agentic processes, I believe there’s also some deadlines set within the finance realm for post quantum.

It’s my plan to get good at PKI to the point I can pitch myself as a PKI specialist, I do very much enjoy it but is it a good choice?


r/PKI Jul 31 '26

Brother home laser printer TLS certificate lifespan of 111 years

0 Upvotes

Been playing around with network discovery in my own CLM tool. Always find it fascinating to see what network appliances and devices do for default TLS certificate. The interesting one in this scenario is my Wifi Brother laser printer. Printer was released in 2018, but has self-signed certificate with date range 2000 -> 2111. Immediately blows my average certificate lifespan away. Gotta figure out how I can automate the renewal with my CLM (https://www.zaita.com). It obviously doesn't support this printer natively so I suspect some ACME+API in my near future.


r/PKI Jul 29 '26

Is this the best place to discuss Venafi ?

Thumbnail
2 Upvotes

r/PKI Jul 29 '26

Do I need to renew/re-sign the Issuing CA certificate after changing CDP/AIA URLs?

5 Upvotes

Hello,

I have a Microsoft two-tier PKI with the following architecture:

  • Offline Root CA
  • Enterprise Issuing Subordinate CA

I am changing the PKI architecture by adding a dedicated IIS server that will host:

  • CRL Distribution Points (CDP)
  • Authority Information Access (AIA)
  • Online Responder (OCSP)

As a result, I need to update the CDP and AIA extensions on my Issuing CA to point to the new URLs.

My question is:

After adding the new CDP and AIA URLs to the Issuing CA, do I need to renew (re-sign) the Issuing CA certificate from the Offline Root CA, or is it not necessary?

I understand that newly issued end-entity certificates will contain the new CDP/AIA URLs, but I am unsure whether the Issuing CA certificate itself also needs to be renewed so that its own CDP/AIA extensions reference the new locations.

Is renewing the Issuing CA certificate considered a requirement, or is it simply a best practice?

Thank you for your guidance.