Skip to content Book a PKI health check Get incident support

Field notes

Technical writing for the people who operate trust.

Practical explanations of ADCS attack paths, certificate failure modes, key custody and cryptographic change — written to support decisions, not chase headlines.

Issue 001—005

The launch reading list.

  1. 01

    ADCS
    7 min read

    The ADCS misconfigurations attackers look for first

    A practical review order for certificate templates, enrolment rights and web endpoints that can turn a normal domain account into a privileged identity.

    Read note
  2. 02

    PKI Operations
    6 min read

    Why certificate outages keep happening

    Expiry is usually the final symptom. The underlying problem is an incomplete lifecycle with no reliable owner, inventory or renewal proof.

    Read note
  3. 03

    PKI Operations
    8 min read

    Designing a two-tier PKI for the next decade

    The hierarchy is the easy diagram. The important decisions are custody, publication, recovery and how change will be governed.

    Read note
  4. 04

    HSM
    5 min read

    What actually happens in an HSM key ceremony

    A ceremony is a controlled production change: named roles, witnessed actions, verified outputs and a recovery path that is tested before the room clears.

    Read note
  5. 05

    Post-Quantum
    6 min read

    Post-quantum readiness: a pragmatic first step

    Do not begin by buying a new algorithm. Begin by finding where cryptography lives, how long the protected data matters and which systems can change.

    Read note

Research notes

Useful enough to keep.
Quiet enough for your inbox.

Occasional field notes on PKI operations, ADCS security and cryptographic change. No trend summaries and no generic security newsletter.

Unsubscribe at any time. No list sharing.