Shivam Sharma
Director & Engineering Lead
Shivam is the Director and Engineering Lead at QCecuring. He architects enterprise PKI, certificate lifecycle management, and cryptographic infrastructure solutions for organizations across industries.
106 articles published
Post Quantum Cryptography
ML-KEM (Kyber) Explained: The Post-Quantum Key Encapsulation StandardUnderstand ML-KEM (formerly CRYSTALS-Kyber), NIST's FIPS 203 post-quantum key encapsulation mechanism. Covers how lattice-based cryptography works, parameter sets, performance benchmarks, hybrid TLS deployment, and migration timeline.
11 May, 2026 · 07 Mins read
PKI
PKI Management Tools Comparison: Open Source vs Enterprise (2026)Compare PKI management tools — EJBCA, Smallstep, Vault PKI, cert-manager, AD CS, and enterprise CLM platforms. Covers features, scalability, compliance, cost, and selection criteria for every organization size.
11 May, 2026 · 05 Mins read
DevOps
Sigstore Cosign Keyless Signing with GitHub Actions OIDC: Complete GuideImplement keyless container image signing with Sigstore Cosign and GitHub Actions OIDC. Covers setup, verification, policy enforcement, SLSA provenance, and production deployment patterns.
11 May, 2026 · 06 Mins read
SSL/TLS
X.509 Certificate Fields Explained: Serial, Thumbprint, SAN, Key Algorithm & ExtensionsUnderstand every field in an X.509 certificate — serial number, subject, issuer, SAN, key usage, thumbprint, and extensions. Includes OpenSSL decoding examples and real-world troubleshooting for each field.
11 May, 2026 · 08 Mins read
SSL/TLS
OpenSSL Complete Guide: Commands, Configuration & TroubleshootingMaster OpenSSL with this comprehensive guide covering certificate generation, CSR creation, chain verification, TLS debugging, format conversion, and production hardening. Every command you'll ever need.
10 May, 2026 · 08 Mins read
CLM
QCecuring vs Venafi (CyberArk): Certificate Lifecycle Management ComparedA detailed, honest comparison of QCecuring SSL Certificate Lifecycle Management vs Venafi TLS Protect (now CyberArk Machine Identity Security) for enterprise certificate lifecycle management. Features, pricing, deployment, architecture, and who each platform is best for.
10 May, 2026 · 08 Mins read
Standards
What is X.509X.509 defines the format for digital certificates used in TLS, code signing, email encryption, and PKI. Here's what's inside an X.509 certificate, how extensions work, and where format issues cause failures.
08 May, 2026
Cryptography fundamentals
Key Exchange (Diffie-Hellman, ECDHE)Key exchange lets two parties derive a shared secret over an insecure channel without transmitting the secret itself. Here's how DH and ECDHE work, why ephemeral keys provide forward secrecy, and where key exchange fails.
06 May, 2026
Clm
Certificate Outages: The $500K Problem Nobody Budgets ForExpired certificates cause more outages than cyberattacks. Here's the real cost of certificate outages, why they keep happening, and the engineering practices that eliminate them.
05 May, 2026 · 05 Mins read
Cryptography fundamentals
Elliptic Curve Cryptography (ECC)ECC provides equivalent security to RSA with dramatically smaller keys and faster operations. Here's how elliptic curves work, which curves to use, and why ECC dominates modern TLS deployments.
28 Apr, 2026
Ready to Secure Your Enterprise?
Experience how our cryptographic solutions simplify, centralize, and automate identity management for your entire organization.