Blog
Insights on certificate management, automation, and the evolving TLS landscape.
Case study: TLS for internal services without DNS credentials on the proxy
How we moved an internal Caddy gateway from per-host Let's Encrypt certificates and a DNS API token to a single KrakenKey wildcard certificate, and what the migration showed about reverse proxies, DNS-01 validation and our own product.
September releases: DNS checks and renewal fixes
CLI, probe and certificate action releases tighten file permissions and failure handling. September app merges add DNS delegation checks and organization dissolution retry fixes.
ACME's Persistent DNS Challenge Drops the Plaintext Account URL
draft-ietf-acme-dns-persist-02 replaces the accounturi in _validation-persist records with a hash bound to the account key and the domain it sits on. Records provisioned against -01 stop validating, and the value can no longer be templated across a fleet.
SSL.com Revoked 2,700 Certificates Over Missing MPIC Evidence
An annual WebTrust audit sampled four certificates and found no Multi-Perspective Issuance Corroboration evidence behind their domain validation. The investigation reached 2,700 certificates, all revoked inside 24 hours. The MPIC quorum steps up again on December 15.
SC104 Passes: The AIA Extension Is No Longer Mandatory in Subscriber Certificates
CA/Browser Forum Ballot SC104 changes authorityInformationAccess from MUST to SHOULD in TLS subscriber certificates. Two lines of redline, and the practical effect is that AIA chain repair stops being something you can rely on.
ACME's New Proof-of-Possession Extension Drops the CSR for KEM Keys
draft-ietf-acme-pop-00 lets ACME clients prove key possession without a PKCS#10 CSR, which ML-KEM keys can't self-sign. This covers the mechanism and what it means for anyone piloting post-quantum certificates.
CVE-2026-62243: Netty's Hostname Verification Fix Undid Itself on Java 25
A patch that restored TLS hostname verification for Netty's OpenSSL client path quietly stopped working on Java 25, because the reflection trick it relied on no longer works. This covers the mechanism and how to check whether you're affected.
CVE-2026-71290: Apache HttpComponents' Async Client Silently Skips Hostname Verification
A critical flaw in Apache HttpComponents Client 5.4-5.6.3 means the async transport ignores HostnameVerificationPolicy.BUILTIN entirely. Any valid certificate for any domain passes. How to check whether you're affected, and how to reproduce it.
SC100 Passes: DNSSEC Validation Requirements Move to Section 4.2.2.2
CA/Browser Forum Ballot SC100 passed on August 6, consolidating scattered DNSSEC validation language into a single section and clarifying that DNSSEC validation is mandatory only on the Primary Network Perspective, which matters for anyone renewing certificates on DNSSEC-signed zones.
FreeRDP's TLS Certificate Validation Bug Is the Null-Prefix Attack, Again
CVE-2026-66402 shows FreeRDP accepting mismatched server certificates due to strlen()-based SAN parsing, a CN fallback, and missing iPAddress SAN checks. Fixed in 3.29.0, and it's the same bug class from 2009.
Two Mass Revocations in Ten Days: HARICA's CP/CPS Drift Problem
HARICA revoked 66,105 certificates for a stale clientAuth EKU on July 20, then forced replacement of every cert issued since March for a missing OCSP AIA pointer on July 25. Both incidents trace to the same root cause: policy documents and issuance systems that stopped agreeing with each other.
Mozilla Root Store Policy v3.1: Mass Revocation Planning Becomes a Trust Requirement
CA/Browser Forum Ballot SC-089 required CAs to build and test a Mass Revocation Plan starting December 2025. Mozilla's Root Store Policy v3.1, effective July 1, folds that requirement into Firefox's trust criteria. This post covers what changed and how to check whether your own certificates are revoked before your monitoring notices.
Let's Encrypt Picks Merkle Tree Certificates for Post-Quantum TLS
On June 3, Let's Encrypt committed to adopting Merkle Tree Certificates as its path to post-quantum web authentication. Here is how MTCs work, why the handshake size math forces the choice, and what ACME operators need to track.
Certificate Transparency Opt-Outs Are Gone
DigiCert removed CT logging opt-out options from CertCentral on June 1, 2026. Chrome Root Program Policy v1.8 Section 1.3.4.1 requires all Root Program participants to log precertificates before issuance by June 15. Internal hostnames on public certificates are now permanently visible in CT logs.
The clientAuth EKU Is Gone from Public TLS Intermediates
Sectigo and DigiCert revoked their multi-purpose intermediate CAs on May 15. Chrome's June 15 CCADB deadline arrives in 19 days. What breaks on your next certificate renewal, and what needs to move to private PKI.
SC-098v2 Passes: RFC 8657 CAA Parameters Are Mandatory from March 2027
CA/Browser Forum Ballot SC-098v2 passed on May 13, requiring all publicly-trusted CAs to process the accounturi and validationmethods CAA parameters from RFC 8657. CAA records that carry those parameters stop being advisory on March 15, 2027.
Let's Encrypt's Generation Y Intermediates Go Live Today
On May 8, Let's Encrypt stopped issuing certificates for 2.5 hours due to a cross-signing problem with the new Generation Y root. Today the planned transition completes. This covers what changes in your cert chain and what to check.
We Built a Free TLS Scanner (And Why We're Giving It Away)
Scan any TLS endpoint for free: certificate details, chain validation, cipher suites, and trust status in seconds. What it checks, how it compares to SSL Labs, and why it's free.
Post-Quantum TLS Is Coming. Every Certificate You Own Will Be Reissued.
Two changes are converging on certificate management: shrinking lifetimes (47 days by 2029) and mandatory post-quantum migration (by 2035). What that means for certificate operations and how to prepare.
Endpoint Monitoring: Know When Your TLS Is Broken Before Your Users Do
KrakenKey now monitors your TLS endpoints from multiple regions, catching misconfigurations, expiring certificates, and broken chains before they cause outages.
The 200-Day TLS Era Is Here, and Shorter Lifetimes Are Coming
CA/B Forum SC-081 is now in effect. TLS certificate lifetimes have dropped to 200 days, then drop to 100 and 47. What changed, where certbot stops, and what KrakenKey adds on top of ACME.
Your AI Agent Can Manage Your TLS Certificates
KrakenKey ships agent-ready API and CLI tool definitions so AI coding agents can issue, renew, and manage TLS certificates autonomously.
Introducing KrakenKey: Automated TLS Certificate Management
KrakenKey automates TLS certificate issuance for developers. Privacy-first with client-side CSR generation, automated DNS-01 challenges, and certificates issued in ~4 minutes.