live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
releaseSECURITY

Red Hat Certificate System 11 brings post-quantum algorithms into enterprise PKI

The Dogtag-based certificate authority adds ML-DSA signatures and ML-KEM key encapsulation while integrating with RHEL cryptographic policy and automated enrollment.

Classical PKI versus post-quantum certificate authority.
AI-generated illustration
By The News Desk· Sep 9, 2026the quick take — two AI hosts go live when you do

Red Hat Certificate System 11 now supports the standardized post-quantum algorithms ML-DSA for digital signatures and ML-KEM for key encapsulation. The change puts quantum-resistant certificate issuance and lifecycle management into Red Hat’s Dogtag-based enterprise public-key infrastructure rather than leaving it as an application-by-application experiment.

What changed

Red Hat says Certificate System 11 can issue, manage and revoke X.509 post-quantum certificates across hybrid-cloud environments. It integrates with RHEL Global Cryptographic Policies, allowing administrators to change the operating system’s cryptographic posture centrally instead of reconfiguring each application separately.

The product supports automated enrollment through EST and ACME and provides certificate-authority, key-recovery and Online Certificate Status Protocol services. Red Hat positions those existing lifecycle functions as important for post-quantum adoption because larger keys, transitional dual signatures and shorter certificate lifetimes can multiply renewal work.

The company also points to an Ansible Automation Platform discovery workflow for finding legacy certificates and other cryptographic attributes across a fleet. That creates a two-stage migration path: inventory classical cryptography first, then use Certificate System as the trust anchor for replacement credentials.

Who should care

The immediate audience is platform-security and PKI teams responsible for long-lived sensitive data, regulated systems or large hybrid estates. Developers are affected indirectly: moving algorithm policy and certificate rotation into shared infrastructure can reduce the number of cryptographic decisions embedded in individual applications.

The release does not make every application post-quantum-safe by itself. Protocol compatibility, certificate-chain size, hardware security modules, clients and network devices still need testing. A certificate authority that can issue ML-DSA or use ML-KEM is one dependency in a migration, not the whole migration.

What to do

Teams should begin with an inventory of certificates, algorithms, expiration periods and application dependencies. They should identify systems that must retain confidentiality for many years and test hybrid or post-quantum chains in representative environments before changing fleet-wide policy.

Certificate System 11’s RHEL policy integration and automated enrollment are the operational features to validate first. Administrators should measure handshake and payload changes, confirm client support, and rehearse rollback. Red Hat’s announcement establishes product capability, but each organization still needs a staged interoperability plan before replacing classical public-key cryptography in production.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.