Practice 01
Cryptographic Infrastructure
Root and issuing CA design, key ceremonies under dual control, custody in FIPS 140-3 Level 3 hardware, and a migration path to ML-KEM / ML-DSA (FIPS 203 / 204) before RSA-2048 and P-256 are deprecated in 2030 and disallowed in 2035.
Engagement parameters
PartnersThales (Luna HSM, listed partner) · SSL.com (public CA, listed partner)HardwareThales Luna · Entrust nShield · Utimaco · YubiHSM 2 — FIPS 140-3 L3 · PKCS#11 · KMIPEcosystemDigiCert · Sectigo · GlobalSign · Verisign registry PKI · ETSI/WebTrust auditorsAlgorithmsECDSA P-384 · Ed25519 · ML-KEM-768 · ML-DSA-65 · SLH-DSAStandardsFIPS 203/204/205 · RFC 5280 · 6960 · 8555 · 3161 · CA/B BRDeliverablesCP/CPS · CBOM · ceremony scripts · runbooks
Data sheet · A4 · SP-SVC-01Open PDF sheet
Operators · identities withheld
Named to clients under NDA at scopingReferences
What this practice is currently working against.
Next: Offensive Security →
