Shivam Sharma
Director & Engineering Lead
Shivam is the Director and Engineering Lead at QCecuring. He architects enterprise PKI, certificate lifecycle management, and cryptographic infrastructure solutions for organizations across industries.
106 articles published
Protocols
What is CMP (Certificate Management Protocol)CMP (RFC 4210/9483) is the most comprehensive certificate management protocol, handling enrollment, renewal, revocation, key update, and cross-certification. Here's how it works, where it's used, and why it's complex but powerful.
26 Apr, 2026
Cryptography fundamentals
What is HashingA cryptographic hash function produces a fixed-size fingerprint from any input. Here's how hashing works, why it's irreversible, and where it's used in certificates, signatures, and integrity verification.
24 Apr, 2026
Machine identity
Machine Identity vs Human IdentityMachine identities outnumber human identities 45:1 but are managed with far less rigor. Here's how they differ in lifecycle, scale, and risk — and why treating them the same way fails.
23 Apr, 2026
Protocols
What is SCEP (Simple Certificate Enrollment Protocol)SCEP enables network devices and endpoints to request certificates from a CA using simple HTTP operations. Here's how it works, why it's still everywhere despite being outdated, and where it creates security gaps.
22 Apr, 2026
Kubernetes
What is cert-managercert-manager automates TLS certificate issuance and renewal in Kubernetes using ACME, Vault, private CAs, and more. Here's how it works, how to configure it, and where it fails silently.
20 Apr, 2026
Kubernetes
Service Mesh and mTLS (Istio, Linkerd)Service meshes like Istio and Linkerd automate mTLS between pods — issuing certificates, rotating them, and encrypting traffic without application code changes. Here's how it works and where it breaks.
18 Apr, 2026
Key management
Key Generation Best PracticesKey generation is the most critical moment in a key's lifecycle — weak generation undermines everything built on top. Here's how to generate keys securely across different environments and what mistakes to avoid.
14 Apr, 2026
Compliance
FIPS 140-3 Compliance: What Changed from 140-2 and How to Achieve ItFIPS 140-3 replaced 140-2 for cryptographic module validation. Here's what changed, what the security levels mean, and a practical guide to achieving FIPS compliance for your cryptographic infrastructure.
10 Apr, 2026 · 05 Mins read
Devsecops
Infrastructure as Code and PKIInfrastructure as Code (IaC) brings PKI under version control — declaring certificates, CAs, and trust configurations as code. Here's how to manage PKI with Terraform, Ansible, and GitOps, and where IaC and certificates conflict.
10 Apr, 2026
Ready to Secure Your Enterprise?
Experience how our cryptographic solutions simplify, centralize, and automate identity management for your entire organization.