R
Richard Hicks
Microsoft MVP consultant and founder of Richard M. Hicks Consulting, Inc. specializing in PKI, enterprise mobility, and secure remote access with 30+ years of experience.
2
APPEARANCES
2
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
Jun 23, 2026
Richard Hicks on 47-Day Certificates, ACME, and Post-Quantum PKI
I
11:23IgalHOST
I'm going to be super excited.
R
11:26Richard HicksGUEST
So, yeah, so with regards to certificate rotation, automation is going to be key, right? We are going to have to automate this.
13 MINS LATER
A
24:23AaronHOST
yeah that's actually maybe a good segue into more of the private pki side we spent a good amount of time on on public but earlier on you mentioned that this movement to 47 days and a lot of the kind of strict uh deadlines being put on for public certificates doesn't apply to the private side but i'm curious uh what when you go in and and help companies of any size with their private pki for issuing their internal certificates What are the validity periods and timelines you typically recommend? Is it one size fits all or kind of how do you break those down based on the use case?
UEFI Secure Boot with Richard Hicks
R
15:31Richard HicksGUEST
If you go to, I think it's, um, aka.ms/um, securebootplaybook, I think is the client version, and securebootforserver is the server version of that.
R
15:47Richard HicksGUEST
I won't rehash that, that here, but ultimately, there's a ton of information for ways to kick off the process, monitor the process, and so forth.
R
15:55Richard HicksGUEST
And, and back to the story I was, I started at the top of the, of the hour here, I wrote a PowerShell script because I was frustrated with the fact that the default command, uh, Get-SecureBoot, um, U- Get-UEFISecureBoot, I think is the command, doesn't return anything that I can readily look at.
6 MINS LATER