<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on Chris Zinda</title><link>https://czinda.io/tags/security/</link><description>Recent content in Security on Chris Zinda</description><generator>Hugo -- 0.146.0</generator><language>en-us</language><lastBuildDate>Thu, 19 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://czinda.io/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Configuring Dogtag PKI Certificate Profiles for IoT with Ansible</title><link>https://czinda.io/posts/dogtag-pki-iot-profiles-ansible/</link><pubDate>Thu, 19 Feb 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/dogtag-pki-iot-profiles-ansible/</guid><description>How to build and automate Dogtag PKI certificate profiles for IoT device enrollment using EST, Ansible, and Red Hat Certificate System — covering constrained device enrollment, post-quantum key sizing, and certificate lifetimes aligned with SC-081v3.</description></item><item><title>OCSP vs CRL Sharding: Measuring Revocation Checking at Scale</title><link>https://czinda.io/posts/ocsp-vs-crl-sharding-performance/</link><pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/ocsp-vs-crl-sharding-performance/</guid><description>A hands-on comparison of OCSP and CRL sharding for certificate revocation checking, with real measurements of wire size, latency, and TLS overhead from a live PKI deployment.</description></item><item><title>Event-Driven Certificate Lifecycle Management with Ansible</title><link>https://czinda.io/posts/event-driven-certificate-revocation-lab/</link><pubDate>Thu, 12 Feb 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/event-driven-certificate-revocation-lab/</guid><description>Automating the full certificate lifecycle — from issuance to revocation — using Event-Driven Ansible, Dogtag PKI, FreeIPA, UBI minimal containers, and post-quantum ML-DSA-87 certificates in an industry moving toward CRL-based revocation and 47-day cert lifetimes.</description></item></channel></rss>