Skip to content

Product1 publisher2 min readPublished

Microsoft tests post-quantum TLS issuance with seven certificate authorities outside public trust

Microsoft's Trusted Root Program is running a pilot where participating certificate authorities can test issuance and compatibility against its platform in a controlled environment. DigiCert is the only participant named.

The Product Desk · Product desk

Illustration accompanying Microsoft tests post-quantum TLS issuance with seven certificate authorities outside public trust

What happened

  • Microsoft's Trusted Root Program is running a post-quantum cryptography pilot for TLS that is deliberately kept outside production and outside public trust scenarios.
  • Microsoft counts vendor dependencies as part of its readiness program, and Goodley said early coordination with those suppliers can expose compatibility and deployment constraints.
  • Goodley described the program in an interview with DigiCert chief trust officer Lakshmi Hanspal at DigiCert's World Quantum Readiness Day, broadcast on theCUBE.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The pilot excludes public trust, so a CA that passes still cannot hand a customer a post-quantum certificate that Windows will accept in the field. Nothing in an operator's renewal queue moves on the strength of it.
  • decision Only DigiCert is identified and six seats are still unknown, so buyers have a cheap qualifying question for their certificate vendor.
  • exposure The participants are certificate authorities, so the load balancers, appliances and device firmware in a customer's own TLS path stay outside the controlled environment and remain their owner's problem.
  • capability Chain-level breakage between an issuer and a validating platform can be found in a lab by whoever caused it, instead of in a customer's renewal window by whoever inherited it.

Anyone who keeps a certificate inventory has two columns that matter here: the thing that terminates TLS, and the certificate authority that issued its certificate. Microsoft's pilot works the second column against Windows. "Certificate authorities can test issuance and compatibility with the Microsoft platform capabilities in a controlled environment," said Karina Sirota Goodley, a senior security product manager at Microsoft [3][7]. "That matters because no individual component can declare success. The whole chain has to work," she said [4].

The pilot sits outside production and public trust scenarios [1]. A customer's machine will not accept a certificate issued inside it, and the person maintaining the inventory has nothing to deploy this quarter. The pilot is for the CAs and for Microsoft's platform team. The operator benefits later, if both sides find the incompatibilities first.

Seven CAs are participating and Goodley named DigiCert [2]. She did not name the other six [13]. The interview ran on theCUBE at DigiCert's own World Quantum Readiness Day, an event for which theCUBE is a paid media partner [8][9]. The account does not say which algorithms are under test, what counts as a pass, or when post-quantum certificates enter public trust [14].

The work described in this pilot is a supplier and a platform checking whether one can issue what the other will parse. Goodley put the ordering plainly. "At Microsoft, the goal isn't to create a cryptographically interesting solution and then search for a use case," she said. "It's to start with a real customer or business problem, understand the operational constraints and build something that works across platforms, protocols, CAs, devices and existing infrastructure. In the post-quantum transition, practical interoperability and measurable risk reduction matter more than being crypto cool" [5].

Microsoft counts vendor dependencies inside its readiness program instead of leaving them until later, and Goodley said early coordination can expose compatibility and deployment constraints [10]. Her instruction to suppliers was blunt: "Make PQC migration your problem before it becomes your customer's problem," she said [11].

The useful list for a team with a 2027 or 2028 migration date on a slide has two entries per row: who issues the certificate for this endpoint, and what validates it. Where the issuer has tested against the validator, the date can be defended. Where neither has, the date is a placeholder. The pilot is the reason it will stay one until the CA can say which side broke. "Customers shouldn't have to become cryptographers to prepare for the quantum era," Goodley said [12].

What to watch

  • Whether Microsoft names the other six participating certificate authorities or publishes pass criteria for the pilot.
  • Whether any of the seven CAs begins offering post-quantum test certificates to customers outside Microsoft's controlled environment.
  • Whether the Trusted Root Program sets a date for post-quantum certificates in public trust.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories