<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Krestfield]]></title><description><![CDATA[Secure Your Digital Future Today]]></description><link>https://www.krestfield.com/blog</link><generator>RSS for Node</generator><lastBuildDate>Thu, 07 May 2026 16:28:28 GMT</lastBuildDate><atom:link href="https://www.krestfield.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[PQC Transition Mechanisms]]></title><description><![CDATA[The transition to post‑quantum cryptography (PQC) presents a fundamental challenge: organisations must adopt PQC algorithms while maintaining the operation of a vast ecosystem of systems, devices, and protocols that may only understand classical cryptography. Although, no single certificate format solves this problem universally. Three main certificate‑based approaches have emerged, each offering different trade‑offs between backward compatibility, security, and long‑term architectural...]]></description><link>https://www.krestfield.com/post/understanding-certificate-management-in-cybersecurity</link><guid isPermaLink="false">69d90f2e61f85fcf9f7bd867</guid><pubDate>Fri, 10 Apr 2026 14:54:38 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/9d40ad_0667745493974bb3ac575dfae0476595~mv2.png/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Krestfield</dc:creator></item><item><title><![CDATA[Reduction of Public TLS Certificate Lifetimes]]></title><description><![CDATA[Implications of CA/Browser Forum Ballot SC‑081v3 for Public and Private PKI The CA/Browser Forum approved Ballot SC‑081v3, introducing a staged reduction in the maximum permitted lifetime of publicly‑trusted TLS certificates. Between 2026 and 2029, certificate validity will decrease from 297 days to 47 days, with reductions applied annually. These requirements apply exclusively to Public CAs. Private enterprise CAs are not subject to these rules and may continue to define certificate...]]></description><link>https://www.krestfield.com/post/the-importance-of-digital-signatures-for-businesses</link><guid isPermaLink="false">69d90f28b1404b5ae2d5cbed</guid><pubDate>Fri, 10 Apr 2026 14:54:32 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/9d40ad_55fdbd89b23147a1ad0fd9af4c27c31d~mv2.png/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Krestfield</dc:creator></item><item><title><![CDATA[Certificate Automation Considerations]]></title><description><![CDATA[The Problem As certificate volumes increase and validity periods shorten, manual certificate management becomes increasingly unsustainable. Human-driven processes are inherently error-prone, difficult to scale, and often dependent on specialised knowledge held by a small number of individuals. Missed renewals, misconfigurations, and inconsistent implementations can lead to service outages, security incidents, and significant business impact. In live environments, automation is no longer a...]]></description><link>https://www.krestfield.com/post/choosing-the-right-pki-software-for-your-needs</link><guid isPermaLink="false">69d90f284750526d40bcc4d7</guid><pubDate>Fri, 10 Apr 2026 14:54:32 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/9d40ad_e7f9a7e5db9040129682af76d9bab7a5~mv2.png/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Krestfield</dc:creator></item></channel></rss>