KrakenKey is live with free and paid plans. Issue your first TLS certificate in minutes.

Blog

Insights on certificate management, automation, and the evolving TLS landscape.

October 3, 2026

Case study: TLS for internal services without DNS credentials on the proxy

How we moved an internal Caddy gateway from per-host Let's Encrypt certificates and a DNS API token to a single KrakenKey wildcard certificate, and what the migration showed about reverse proxies, DNS-01 validation and our own product.

engineeringacmednscertificate-transparencyproduct
September 30, 2026

September releases: DNS checks and renewal fixes

CLI, probe and certificate action releases tighten file permissions and failure handling. September app merges add DNS delegation checks and organization dissolution retry fixes.

release-notesproductacme
September 23, 2026

ACME's Persistent DNS Challenge Drops the Plaintext Account URL

draft-ietf-acme-dns-persist-02 replaces the accounturi in _validation-persist records with a hash bound to the account key and the domain it sits on. Records provisioned against -01 stop validating, and the value can no longer be templated across a fleet.

acmednspki
September 16, 2026

SSL.com Revoked 2,700 Certificates Over Missing MPIC Evidence

An annual WebTrust audit sampled four certificates and found no Multi-Perspective Issuance Corroboration evidence behind their domain validation. The investigation reached 2,700 certificates, all revoked inside 24 hours. The MPIC quorum steps up again on December 15.

ca-incidentscabforumpki
September 9, 2026

SC104 Passes: The AIA Extension Is No Longer Mandatory in Subscriber Certificates

CA/Browser Forum Ballot SC104 changes authorityInformationAccess from MUST to SHOULD in TLS subscriber certificates. Two lines of redline, and the practical effect is that AIA chain repair stops being something you can rely on.

cabforumpki
September 2, 2026

ACME's New Proof-of-Possession Extension Drops the CSR for KEM Keys

draft-ietf-acme-pop-00 lets ACME clients prove key possession without a PKCS#10 CSR, which ML-KEM keys can't self-sign. This covers the mechanism and what it means for anyone piloting post-quantum certificates.

acmepost-quantumpki
August 26, 2026

CVE-2026-62243: Netty's Hostname Verification Fix Undid Itself on Java 25

A patch that restored TLS hostname verification for Netty's OpenSSL client path quietly stopped working on Java 25, because the reflection trick it relied on no longer works. This covers the mechanism and how to check whether you're affected.

cvetls
August 19, 2026

CVE-2026-71290: Apache HttpComponents' Async Client Silently Skips Hostname Verification

A critical flaw in Apache HttpComponents Client 5.4-5.6.3 means the async transport ignores HostnameVerificationPolicy.BUILTIN entirely. Any valid certificate for any domain passes. How to check whether you're affected, and how to reproduce it.

cvetls
August 12, 2026

SC100 Passes: DNSSEC Validation Requirements Move to Section 4.2.2.2

CA/Browser Forum Ballot SC100 passed on August 6, consolidating scattered DNSSEC validation language into a single section and clarifying that DNSSEC validation is mandatory only on the Primary Network Perspective, which matters for anyone renewing certificates on DNSSEC-signed zones.

dnscabforum
August 5, 2026

FreeRDP's TLS Certificate Validation Bug Is the Null-Prefix Attack, Again

CVE-2026-66402 shows FreeRDP accepting mismatched server certificates due to strlen()-based SAN parsing, a CN fallback, and missing iPAddress SAN checks. Fixed in 3.29.0, and it's the same bug class from 2009.

cvetls
July 29, 2026

Two Mass Revocations in Ten Days: HARICA's CP/CPS Drift Problem

HARICA revoked 66,105 certificates for a stale clientAuth EKU on July 20, then forced replacement of every cert issued since March for a missing OCSP AIA pointer on July 25. Both incidents trace to the same root cause: policy documents and issuance systems that stopped agreeing with each other.

ca-incidentscabforumroot-programs
July 8, 2026

Mozilla Root Store Policy v3.1: Mass Revocation Planning Becomes a Trust Requirement

CA/Browser Forum Ballot SC-089 required CAs to build and test a Mass Revocation Plan starting December 2025. Mozilla's Root Store Policy v3.1, effective July 1, folds that requirement into Firefox's trust criteria. This post covers what changed and how to check whether your own certificates are revoked before your monitoring notices.

root-programsca-incidentscabforum
June 24, 2026

Let's Encrypt Picks Merkle Tree Certificates for Post-Quantum TLS

On June 3, Let's Encrypt committed to adopting Merkle Tree Certificates as its path to post-quantum web authentication. Here is how MTCs work, why the handshake size math forces the choice, and what ACME operators need to track.

post-quantumlets-encryptcertificate-transparency
June 3, 2026

Certificate Transparency Opt-Outs Are Gone

DigiCert removed CT logging opt-out options from CertCentral on June 1, 2026. Chrome Root Program Policy v1.8 Section 1.3.4.1 requires all Root Program participants to log precertificates before issuance by June 15. Internal hostnames on public certificates are now permanently visible in CT logs.

certificate-transparencyroot-programs
May 27, 2026

The clientAuth EKU Is Gone from Public TLS Intermediates

Sectigo and DigiCert revoked their multi-purpose intermediate CAs on May 15. Chrome's June 15 CCADB deadline arrives in 19 days. What breaks on your next certificate renewal, and what needs to move to private PKI.

root-programsca-incidentspki
May 20, 2026

SC-098v2 Passes: RFC 8657 CAA Parameters Are Mandatory from March 2027

CA/Browser Forum Ballot SC-098v2 passed on May 13, requiring all publicly-trusted CAs to process the accounturi and validationmethods CAA parameters from RFC 8657. CAA records that carry those parameters stop being advisory on March 15, 2027.

dnscabforum
May 13, 2026

Let's Encrypt's Generation Y Intermediates Go Live Today

On May 8, Let's Encrypt stopped issuing certificates for 2.5 hours due to a cross-signing problem with the new Generation Y root. Today the planned transition completes. This covers what changes in your cert chain and what to check.

lets-encryptacmepki
May 2, 2026

We Built a Free TLS Scanner (And Why We're Giving It Away)

Scan any TLS endpoint for free: certificate details, chain validation, cipher suites, and trust status in seconds. What it checks, how it compares to SSL Labs, and why it's free.

productmonitoring
April 19, 2026

Post-Quantum TLS Is Coming. Every Certificate You Own Will Be Reissued.

Two changes are converging on certificate management: shrinking lifetimes (47 days by 2029) and mandatory post-quantum migration (by 2035). What that means for certificate operations and how to prepare.

post-quantumcertificate-lifetimes
April 1, 2026

Endpoint Monitoring: Know When Your TLS Is Broken Before Your Users Do

KrakenKey now monitors your TLS endpoints from multiple regions, catching misconfigurations, expiring certificates, and broken chains before they cause outages.

productmonitoring
March 27, 2026

The 200-Day TLS Era Is Here, and Shorter Lifetimes Are Coming

CA/B Forum SC-081 is now in effect. TLS certificate lifetimes have dropped to 200 days, then drop to 100 and 47. What changed, where certbot stops, and what KrakenKey adds on top of ACME.

certificate-lifetimesproductlets-encrypt
March 25, 2026

Your AI Agent Can Manage Your TLS Certificates

KrakenKey ships agent-ready API and CLI tool definitions so AI coding agents can issue, renew, and manage TLS certificates autonomously.

productcertificate-lifetimes
March 18, 2026

Introducing KrakenKey: Automated TLS Certificate Management

KrakenKey automates TLS certificate issuance for developers. Privacy-first with client-side CSR generation, automated DNS-01 challenges, and certificates issued in ~4 minutes.

productcertificate-lifetimes