Two Metrics That Matter: Measuring PQC Readiness
This is the fifth and final post in a series based on my PA TechCon 2026 talk. The previous posts covered the threat model, procurement, and the local government gap. This one is about how you know whether any of it is working. The Dashboard Problem Every PQC migration plan I have reviewed includes a reporting section. Most of them propose a dashboard with fifteen to thirty metrics: certificate inventory completion percentage, vendor compliance attestation counts, HSM firmware versions, policy document status, training completion rates, risk assessment coverage, and a constellation of RAG indicators that someone updates monthly in a spreadsheet they email to a distribution list nobody reads. ...
The Part With No CISO: PQC Migration for Counties, School Districts, and Small Utilities
This is the fourth post in a series drawn from a talk I gave at PA TechCon 2026. The first post covered the full migration plan. This one focuses on the part of the problem that keeps me up at night: the thousands of local entities that connect to state systems as trusted peers and have no realistic path to running their own post-quantum migration. The numbers for Pennsylvania are specific, but the shape of the problem is universal. Every state has it. ...
Fix Procurement First: The Cheapest PQC Migration Move You Can Make
This is the third post in a series on post-quantum migration for state and local government, based on a talk I gave at PA TechCon 2026. The first post covers the full migration plan. The second explains why the trust integrity threat (TNFL) should set your calendar. This one is about the cheapest thing on the entire list. Every migration conversation I have with a government agency eventually arrives at the same obstacle: “There is no budget this fiscal year.” The answer is always the same. The highest-leverage move you can make for post-quantum readiness does not require budget. It requires a paragraph in your solicitation templates. ...
Trust Now, Forge Later: The PQC Threat Nobody Is Talking About
Every conversation about post-quantum risk starts with the same story: adversaries are recording encrypted traffic today and will decrypt it when quantum computers arrive. That threat — Harvest Now, Decrypt Later (HNDL) — is real, and I covered it in detail in Encryption on Borrowed Time. But HNDL has a twin that gets far less attention, and it is the one that should set your migration calendar. Trust Now, Forge Later (TNFL) uses the same mathematics to attack a different target. Instead of breaking the key exchange that protects a recorded session, it breaks the signature that anchors trust. The result is not exposed data — it is forged identity. And unlike HNDL, there is no cleaning it up after the fact. ...
Encryption on Borrowed Time: A PQC Migration Plan for State Government
I gave this talk at PA TechCon 2026 in Harrisburg on August 13. The audience was Pennsylvania state and local government IT leaders — CIOs, CISOs, procurement officers, and the county IT directors who keep the lights on with two-person teams. The premise fits in one sentence: Pennsylvania’s data has a shelf life measured in decades, and the encryption protecting it has a shelf life measured in years. Nobody has done the subtraction. ...
Securing Critical Infrastructure: Certificate-Based Identity for Water and Utility Systems
In July and August 2026, a coordinated cyberattack struck water systems across more than twelve U.S. states. Over a single weekend, more than thirty Minnesota water utilities lost control of their programmable logic controllers. Operators were locked out of their own equipment. Safety alarms were silently disabled while displays continued to show normal operation. Boil-water advisories went out across multiple states, and facilities fell back to manual operations — dispatching personnel to physically operate pumps and valves. ...
kipuka: An EST Enrollment Server Built for Enterprise PKI
Enterprise certificate enrollment has a tooling problem. Most organizations run a certificate authority — often Red Hat Certificate System (Dogtag), Microsoft AD CS, or EJBCA — but getting certificates onto devices, servers, and workloads still involves brittle SCEP integrations, custom scripts, or manual CSR submission. The enrollment layer is the weak link. EST (Enrollment over Secure Transport) was designed to fix this. Published as RFC 7030 in 2013, it replaces SCEP with a modern HTTPS-based protocol that supports mutual TLS, one-time passwords, and integration with existing CAs. But production-ready EST implementations remain scarce — especially ones that meet government and enterprise compliance requirements. ...
The State of Post-Quantum Cryptography: May 2026
Post-quantum cryptography is no longer a standards exercise. ML-KEM key exchange is the default in every major browser and in OpenSSH. RHEL 10 ships with post-quantum TLS and SSH enabled out of the box. DigiCert is issuing ML-DSA certificates today. But “available” and “deployed” are not the same thing. Key exchange is largely solved. Authentication — the part where certificates, signatures, and trust chains live — is not. The gap between what the standards define and what production systems can actually verify is where most of the engineering work remains. ...
Replacing Six ASN.1 Crates with One: Migrating to Synta
Every X.509 certificate, every CRL, every OCSP response, every CSR is encoded in ASN.1 DER. If you are building PKI software in Rust, ASN.1 encoding and decoding is the foundation everything else rests on. Get it wrong, and certificates parse incorrectly. Get it slow, and your CA cannot keep up with issuance. Get it fragmented across multiple libraries, and you spend more time managing dependencies than building features. PKI.Next was using six ASN.1 crates simultaneously. We replaced all of them with synta in a single commit. This post explains why, how, and what we gained. ...
PKI.Next Part 6: Replacing Dogtag PKI
Dogtag PKI has been Red Hat’s Certificate Authority since 2005. It started as Netscape Certificate Management System, became Red Hat Certificate System, was open-sourced as Dogtag, and is now the CA backend for FreeIPA — Red Hat’s identity management platform that manages certificates, Kerberos, DNS, and SUDO for enterprise Linux environments. Dogtag works. It has passed Common Criteria evaluations. It runs in government agencies, financial institutions, and large enterprises. It has issued millions of certificates in production. ...