Amarjeet Shukla
Software Engineer — SSL/TLS
Amarjeet works on SSL certificate lifecycle management at QCecuring. He writes about TLS protocols, certificate automation, and PKI deployment patterns.
42 articles published
Pki
Certificate Policy and Practice Statement (CP/CPS)A Certificate Policy defines what a CA will do. A Certification Practice Statement defines how it does it. Here's what they contain, why auditors care, and where gaps between CP and CPS create real risk.
04 Apr, 2026
Ssh
SSH Key Management in the Enterprise: The Complete GuideMost enterprises have 10x more SSH keys than they think, with no inventory, no rotation, and no offboarding. Here's how to get SSH key sprawl under control before it becomes a breach.
28 Mar, 2026 · 05 Mins read
Pki
PKI for IoT DevicesIoT devices need cryptographic identity for authentication and encrypted communication. Here's how PKI works at device scale, what's different from server PKI, and where IoT certificate management fails.
28 Mar, 2026
Ssl tls
What is mTLS (Mutual TLS)Mutual TLS (mTLS) requires both client and server to present certificates during the handshake, enabling cryptographic identity verification for service-to-service communication. Here's how it works, where it's deployed, and what breaks.
15 Mar, 2026
Ssl tls
TLS 1.3 vs TLS 1.2TLS 1.3 removed insecure algorithms, reduced handshake latency to 1-RTT, and encrypted more of the handshake. Here's what changed, what was removed, and what breaks during migration.
12 Mar, 2026
Security
Machine Identity Management: Why It's the Biggest Gap in Enterprise SecurityMachine identities outnumber human identities 45:1 but are managed with 10% of the rigor. Here's why this gap exists, what the risks are, and how to build a machine identity management program.
10 Mar, 2026 · 05 Mins read
Ssl tls
Certificate Validity and 90-Day ProposalsCertificate validity periods are shrinking from 398 days to 90 days. Here's why shorter lifetimes reduce risk, what the CA/Browser Forum proposals mean for operations, and how to prepare.
10 Mar, 2026
Ssl tls
What is a TLS HandshakeA TLS handshake is the negotiation process that establishes an encrypted connection between client and server. Here's how TLS 1.3 reduced it to one round trip, what happens at each step, and where it fails.
20 Feb, 2026
Compliance
PCI DSS 4.0 Cryptography Requirements: What Changed and How to ComplyPCI DSS 4.0 introduced new cryptographic requirements including cipher suite inventory, certificate lifecycle documentation, and stronger key management. Here's what's new, what's mandatory by March 2025, and how to prepare.
15 Feb, 2026 · 06 Mins read
Ready to Secure Your Enterprise?
Experience how our cryptographic solutions simplify, centralize, and automate identity management for your entire organization.