Client Authentication EKU Phased Out

This blogpost addresses the upcoming changes regarding the removal of Client Authentication Extended Key Usage (EKU) from publicly trusted SSL/TLS certificates, a shift driven by security concerns and the need for clearer roles in cryptographic operations.

Breaking News: Prepare for 47-Day SSL/TLS Certificates

The CA/Browser Forum Ballot for drastically reducing the maximum lifespan of publicly trusted SSL/TLS certificates has officially passed. Read in this blog post what actions you need to take to ensure you are prepared for this.

DNS CAA S/MIME Resource Check 2025 Required

Starting March 13, 2025 CA’s such as DigiCert will start checking CAA resource records before issuing a Secure Email (S/MIME) certificate with a mailbox address. Read how to check and why this CAA S/MIME resource check is needed.

Email domain validation change policy by CA/B Forum

The CA/B forum has announced a major change to the annual validation of domain names via email. This will impact organizations that purchase certificates from DigiCert and GlobalSign. Read more about the change here.

S/MIME Management and Automation: Challenges & solutions

KeyTalk services

Implementing S/MIME across an entire company is far from straightforward and many organizations struggle with challenges such as mass certificate creation, deployment, configuration, and management. Read more about this in our latest blogpost.