<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Kipuka on Chris Zinda</title><link>https://czinda.io/tags/kipuka/</link><description>Recent content in Kipuka on Chris Zinda</description><generator>Hugo -- 0.146.0</generator><language>en-us</language><lastBuildDate>Thu, 25 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://czinda.io/tags/kipuka/index.xml" rel="self" type="application/rss+xml"/><item><title>kipuka: An EST Enrollment Server Built for Enterprise PKI</title><link>https://czinda.io/posts/kipuka-est-server-and-infrastructure/</link><pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/kipuka-est-server-and-infrastructure/</guid><description>Enterprise certificate enrollment shouldn&amp;#39;t require a monolithic CA. kipuka is a Rust-based EST server with multi-CA failover, HSM key protection, NIAP compliance, CoAP/DTLS for constrained devices, CMP enrollment, and post-quantum readiness — designed to fit into the PKI you already have.</description></item><item><title>The State of Post-Quantum Cryptography: May 2026</title><link>https://czinda.io/posts/state-of-pqc-may-2026/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/state-of-pqc-may-2026/</guid><description>A practitioner&amp;#39;s scorecard for post-quantum cryptography adoption across TLS, SSH, and PKI — what works today, what&amp;#39;s close, and what&amp;#39;s still blocked.</description></item><item><title>Replacing Six ASN.1 Crates with One: Migrating to Synta</title><link>https://czinda.io/posts/migrating-asn1-to-synta/</link><pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/migrating-asn1-to-synta/</guid><description>How PKI.Next replaced six competing ASN.1/X.509 Rust crates with synta — a schema-generated, zero-copy library — in a single migration that touched 34 files, deleted 1,726 lines, and made certificate parsing 3x faster.</description></item><item><title>PKI.Next Part 6: Replacing Dogtag PKI</title><link>https://czinda.io/posts/pki-next-part6-replacing-dogtag/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/pki-next-part6-replacing-dogtag/</guid><description>What twenty years of operating Dogtag PKI taught us about building its replacement, the compatibility proxy that makes migration possible, and the architectural bets that will define the next twenty years of certificate management.</description></item><item><title>PKI.Next Part 5: One CA, Six Protocols</title><link>https://czinda.io/posts/pki-next-part5-protocol-servers/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/pki-next-part5-protocol-servers/</guid><description>How PKI.Next serves EST, ACME, CoAP, SPIFFE/SPIRE, HashiCorp Vault, and Dogtag compatibility from a single CA using the Registration Authority pattern — and why protocol diversity is the future of PKI.</description></item><item><title>PKI.Next Part 4: Tamper-Evident Audit Logs</title><link>https://czinda.io/posts/pki-next-part4-tamper-evident-audit/</link><pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/pki-next-part4-tamper-evident-audit/</guid><description>How PKI.Next implements HMAC hash-chained audit logs for Common Criteria FAU_STG.2 compliance, the timestamp precision bug that silently broke chain verification, and why audit integrity is the hardest part of running a CA.</description></item><item><title>PKI.Next Part 3: FIPS 140-3 and the Crypto Pluggability Problem</title><link>https://czinda.io/posts/pki-next-part3-fips-and-hsm/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/pki-next-part3-fips-and-hsm/</guid><description>How PKI.Next uses Rust feature flags and trait objects to support three cryptographic backends — ring, aws-lc-rs (FIPS 140-3), and PKCS#11 hardware — without a single if-else in the certificate issuance path.</description></item><item><title>PKI.Next Part 1: Building a Certificate Authority in Rust</title><link>https://czinda.io/posts/pki-next-part1-building-ca-in-rust/</link><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/pki-next-part1-building-ca-in-rust/</guid><description>Why we chose Rust to build a modern Certificate Authority from scratch, the modular crate architecture that makes it work, and what 55,000 lines of Rust buys you that Java and C never could.</description></item></channel></rss>