Shivam Sharma
Director & Engineering Lead
Shivam is the Director and Engineering Lead at QCecuring. He architects enterprise PKI, certificate lifecycle management, and cryptographic infrastructure solutions for organizations across industries.
130 articles published
Kubernetes
Service Mesh and mTLS (Istio, Linkerd)Service meshes like Istio and Linkerd automate mTLS between pods — issuing certificates, rotating them, and encrypting traffic without application code changes. Here's how it works and where it breaks.
18 Apr, 2026
Key management
Key Generation Best PracticesKey generation is the most critical moment in a key's lifecycle — weak generation undermines everything built on top. Here's how to generate keys securely across different environments and what mistakes to avoid.
14 Apr, 2026
Compliance
FIPS 140-3 Compliance: What Changed from 140-2 and How to Achieve ItFIPS 140-3 replaced 140-2 for cryptographic module validation. Here's what changed, what the security levels mean, and a practical guide to achieving FIPS compliance for your cryptographic infrastructure.
10 Apr, 2026 · 05 Mins read
Devsecops
Infrastructure as Code and PKIInfrastructure as Code (IaC) brings PKI under version control — declaring certificates, CAs, and trust configurations as code. Here's how to manage PKI with Terraform, Ansible, and GitOps, and where IaC and certificates conflict.
10 Apr, 2026
Pki
PKI Hierarchy Design (1-tier, 2-tier, 3-tier)PKI hierarchy depth determines security, scalability, and operational complexity. Here's when to use 1-tier, 2-tier, or 3-tier designs, what each costs operationally, and where hierarchy choices create long-term pain.
07 Apr, 2026
Code signing
Code Signing in CI/CD PipelinesIntegrating code signing into CI/CD pipelines ensures every build artifact is signed without manual intervention. Here's how to do it securely, where to store signing keys, and what goes wrong in automated signing.
03 Apr, 2026
Code signing
Code Signing CertificatesCode signing certificates are X.509 certificates with Extended Key Usage for code signing. Here's the difference between standard and EV certificates, what CAs require, and how certificate requirements have changed.
02 Apr, 2026
Cryptography
Encryption vs Tokenization: When to Use Each for Data ProtectionEncryption transforms data mathematically. Tokenization replaces it with a random substitute. Here's when each approach is better, how they affect PCI DSS scope, and why most organizations need both.
01 Apr, 2026 · 05 Mins read
Pki
PKI Trust ModelsPKI trust models define how entities establish and verify trust. Here's how hierarchical, mesh, bridge, and web-of-trust models work, where each is used, and what breaks when trust assumptions fail.
01 Apr, 2026
Ready to Secure Your Enterprise?
Experience how our cryptographic solutions simplify, centralize, and automate identity management for your entire organization.