<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TurboLight Solutions</title><link>https://www.turbolightsolutions.com/</link><description>Recent content on TurboLight Solutions</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 06 May 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://www.turbolightsolutions.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Random Number Digest: April 2025</title><link>https://www.turbolightsolutions.com/posts/rnd-april-2025/</link><pubDate>Tue, 06 May 2025 00:00:00 +0000</pubDate><guid>https://www.turbolightsolutions.com/posts/rnd-april-2025/</guid><description>&lt;h2 id="big-news"&gt;Big News&lt;/h2&gt;
&lt;p&gt;After several months of discussion, the CA/Browser Forum &lt;a href="https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/9768xgUUfhQ"&gt;passed ballot SC-81&lt;/a&gt; by a very comfortable margin (all YES or ABSTAIN votes), which is a stark contrast to the ballot for 398-day certificates &lt;a href="https://cabforum.org/2019/09/10/ballot-sc022v2-reduce-certificate-lifetimes/"&gt;a few years ago&lt;/a&gt;. The ballot establishes a maximum validity period of 47 days for publicly trusted TLS certificates, although almost all CAs will cap the validity period at 46 days to comply with the &lt;a href="https://github.com/cabforum/servercert/pull/553/files#diff-e0ac1bd190515a4f2ec09139d395ef6a8c7e9e5b612957c1f5a2dea80c6a6cfeR1964"&gt;SHOULD-level requirement&lt;/a&gt; to not exceed 46 days (the same applies for the other steps of the validity period reduction in the ballot: 199 days for the 200-day maximum validity period, etc.). Additionally, the ballot reduces the reuse period for domain validations from 398 days to 10 days. With a 8.67x reduction in validity period and a whopping 39.8x reduction in validation lifetime, the message is quite clear: organizations need to automate the validation, issuance, and installation of their publicly trusted TLS certificates within the next few years to prepare.&lt;/p&gt;</description></item><item><title>Random Number Digest: March 2025</title><link>https://www.turbolightsolutions.com/posts/rnd-march-2025/</link><pubDate>Fri, 04 Apr 2025 00:00:00 +0000</pubDate><guid>https://www.turbolightsolutions.com/posts/rnd-march-2025/</guid><description>&lt;h2 id="big-news"&gt;Big News&lt;/h2&gt;
&lt;p&gt;Apple&amp;rsquo;s ballot that proposes a maximum validity period of 47 days for TLS certificates — among other things — is still in discussion period at the CA/Browser Forum, but the effective dates of &lt;a href="https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/a6A2Wmu0gUw/m/eDGxwthmBQAJ"&gt;several items have been pushed back&lt;/a&gt;. It is expected that this ballot will go to voting sometime in April.&lt;/p&gt;
&lt;p&gt;X9 &lt;a href="https://x9.org/x9-launches-open-pki-forum-to-guide-new-financial-industry-pki-products/"&gt;launched a forum&lt;/a&gt; for the newly created X9 Financial PKI. The X9 Financial PKI is intended to provide an alternative for using the WebPKI for financial applications. The migration in the WebPKI from SHA-1 was challenging for several financial use cases (such as payment terminals), and this PKI will be operated with those use cases in mind instead of prioritizing browser-based TLS as it is in the WebPKI. The Forum will solicit feedback and suggestions from interested parties to help guide the evolution of the PKI.&lt;/p&gt;</description></item><item><title>Random Number Digest: February 2025</title><link>https://www.turbolightsolutions.com/posts/rnd-february-2025/</link><pubDate>Tue, 04 Mar 2025 00:00:00 +0000</pubDate><guid>https://www.turbolightsolutions.com/posts/rnd-february-2025/</guid><description>&lt;p&gt;What is cryptography but some random numbers mixed with drama? February is the shortest month of the year, but you wouldn&amp;rsquo;t know it looking at the long list of news and happenings from the month.&lt;/p&gt;
&lt;h2 id="big-news"&gt;Big News&lt;/h2&gt;
&lt;p&gt;The discussion on reduced certificate validity periods continues on at the CA/Browser Forum. The &lt;a href="https://github.com/cabforum/servercert/pull/553/commits/abf6c4e3845040069672d58cd2dd80ede8f42012"&gt;latest update to draft ballot SC-81&lt;/a&gt; delays the rollout of the maximum certificate validity period of 47 days from 2028 to 2029. Meanwhile, &lt;a href="https://github.com/cabforum/servercert/pull/553"&gt;a good, old-fashioned Internet flamewar&lt;/a&gt; continues in the comments section of the Github pull request for the ballot.&lt;/p&gt;</description></item><item><title>About</title><link>https://www.turbolightsolutions.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.turbolightsolutions.com/about/</guid><description>&lt;h2 id="professional-background"&gt;Professional background&lt;/h2&gt;
&lt;p&gt;I&amp;rsquo;ve spent over two decades in software engineering, the last decade specialized in PKI, inside
commercial CA operations where compliance and reliability are non-negotiable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this solves for you:&lt;/strong&gt; You&amp;rsquo;re not buying slideware from someone who left the trenches
a decade ago. I&amp;rsquo;ve operated production CA infrastructure under real commercial and audit
pressure, so my recommendations account for operational reality, not just the spec on paper.&lt;/p&gt;
&lt;h2 id="standards-participation"&gt;Standards participation&lt;/h2&gt;
&lt;h3 id="cabrowser-forum-cabf"&gt;CA/Browser Forum (CABF)&lt;/h3&gt;
&lt;p&gt;I&amp;rsquo;ve proposed and endorsed ballots across four working groups and served as Validation Subcommittee Chair for over 4 years.&lt;/p&gt;</description></item><item><title>Contact</title><link>https://www.turbolightsolutions.com/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.turbolightsolutions.com/contact/</guid><description>&lt;h2 id="lets-talk"&gt;Let&amp;rsquo;s talk&lt;/h2&gt;
&lt;p&gt;If you&amp;rsquo;re operating a CA, building PKI into a product, facing a compliance deadline, or
planning for post-quantum migration, reach out and let&amp;rsquo;s discuss how I can help.&lt;/p&gt;
&lt;p&gt;Please provide your contact information below to start the conversation.&lt;/p&gt;
&lt;script src="https://formgrid.dev/embed.js" async&gt;&lt;/script&gt;
&lt;div data-formgrid-form="5i7rx77o"&gt;&lt;/div&gt;</description></item><item><title>Services</title><link>https://www.turbolightsolutions.com/services/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.turbolightsolutions.com/services/</guid><description>&lt;h2 id="custom-pki-software-development"&gt;Custom PKI software development&lt;/h2&gt;
&lt;p&gt;I design and implement CAs, validation logic, certificate tooling, and integrations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The problem this solves:&lt;/strong&gt; You need PKI components that don&amp;rsquo;t exist off the shelf, or your
existing stack doesn&amp;rsquo;t fit your operational and compliance constraints. I build
production-grade software with full command of both the code and the standards it must
satisfy. I eliminate the costly gap between a compliant design and a correct implementation.&lt;/p&gt;</description></item></channel></rss>