Paul van Brouwershaven

29 Followers
160 Following
11 Posts
CEO & Founder of Digitorus | Director Technology Compliance at Entrust | Vice chair at the CA/Browser Forum | Chair at the PKI Consortium | Technologist, Cybercrime, Cryptography, Security, PKI
LinkedInhttps://www.linkedin.com/in/pvanbrouwershaven
Twitterhttps://twitter.com/vanbroup
GitHubhttps://github.com/vanbroup

The model promises comprehensive assessment, benchmarking, and optimization of Public Key Infrastructure (PKI) implementations

#pki #pr #press #security #maturity #pkic #cryptography #news

https://pkic.org/2023/08/10/pki-consortium-unveils-the-first-pki-maturity-model-for-feedback/

PKI Consortium Unveils the first PKI Maturity Model for feedback

The PKI Consortium, a dynamic alliance dedicated to enhancing trust and security within the digital landscape, proudly announces the preview release of its pioneering PKI Maturity Model. A collaborative effort by the PKI Maturity Model Working Group, this model will revolutionize the way organizations can plan, evaluate, and compare Public Key Infrastructure (PKI) implementations.

Take the Go developer survey
https://go.dev/blog/survey2023-h2

#golang

Share your feedback about developing with Go - The Go Programming Language

Help shape the future of Go by sharing your thoughts via the Go Developer Survey

The Council of the European Union and European Parliament reached a provisional political agreement on the core elements of a new framework for a European digital identity (eID).

- The provisional agreement clarifies that the issuance, use for authentication and revocation of wallets should be free of charge to natural persons.
- The wallet will provide the possibility of e-signatures to natural persons free of charge.
- The revised regulation expands the current list of trust services with new qualified trust services, including the provision of electronic ledgers and the management of remote electronic signature and seal creation devices.
- The issuance of electronic attestation of attributes, such as medical certificates or professional qualifications, by qualified providers has been retained from the Commission’s original proposal.
- The press release does not mention any details about QWACs.

Technical work will continue to complete the legal text in accordance with the political agreement. When finalised, the text will be submitted to the member states’ representatives (Coreper) for endorsement. Subject to a legal/linguistic review, the revised regulation will then need to be formally adopted by the Parliament and the Council before it can be published in the EU’s Official Journal and enter into force.

#eidas #eid #eu #signing #wallet #europeanunion #digital

https://www.consilium.europa.eu/en/press/press-releases/2023/06/29/council-and-parliament-strike-a-deal-on-a-european-digital-identity-eid/

A group of Chinese researchers have just published a paper claiming that they can (although they have not yet done so) break 2048-bit RSA

https://www.schneier.com/blog/archives/2023/01/breaking-rsa-with-a-quantum-computer.html

Breaking RSA with a Quantum Computer - Schneier on Security

The RFC defining the Extended Key Usage (EKU) for Document Signing has now been published as RFC 9336!

(1.3.6.1.5.5.7.3.36 - id-kp-documentSigning)

https://rfc-editor.org/rfc/rfc9336.html

#rfc #eku #x509 #certificate #pki #pdf #documentsigning

RFC 9336: X.509 Certificate General-Purpose Extended Key Usage (EKU) for Document Signing

RFC 5280 specifies several extended key purpose identifiers (KeyPurposeIds) for X.509 certificates. This document defines a general-purpose Document-Signing KeyPurposeId for inclusion in the Extended Key Usage (EKU) extension of X.509 public key certificates. Document-Signing applications may require that the EKU extension be present and that a Document-Signing KeyPurposeId be indicated in order for the certificate to be acceptable to that Document-Signing application.

@cloudflare It would be great if we could run a #ActivityPub or #Mastadon backend server as a Cloudflare worker on your own domain!