Categories: Security

Email Certificate Standards Updated to Support ACME Automation & Future PQC Security

Changes to the S/MIME Certificate Baseline Requirements add support for automated mailbox validation (via the ACME protocol) and post-quantum cryptography algorithm testing

July 2025 was a busy period in the CA/Brower Forum’s (CABF) S/MIME Certificate Working Group (SMCWG). There are two key ballots relating to S/MIME certificates that have been approved (SMC013) or adopted (SMC012) in the last month:

  1. SMC012: Introduce ACME for S/MIME was officially adopted as part of the S/MIME Baseline Requirements on July 2. This ballot provides certification authorities (CAs) with a standardized and automated way to respond to mailbox control validation requests using the ACME protocol. This offers another automation-friendly method for CAs to validate mailbox addresses.
  2. SMC013: Enable PQC Algorithms for S/MIME entered a 30-day review period that’s set to end Aug. 20. This ballot aims to add the use of two post-quantum cryptography (PQC) algorithms into the S/MIME Baseline Requirements. These certificates are intended for testing (by CAs and clients) and wouldn’t be generally available. However, this move marks yet another step that on the road that ultimately leads to PQC adoption and usage on public networks.

So, what’s the deal with these two ballots and how are they intended to enhance email security and mailbox domain validations? While these changes won’t directly impact your organization in terms of preparations, our goal is to keep you apprised of the latest S/MIME industry developments.

Let’s hash it out.

The post Email Certificate Standards Updated to Support ACME Automation & Future PQC Security appeared first on Hashed Out by The SSL Store™.

OnlineDocs Manager

Share
Published by
OnlineDocs Manager

Recent Posts

PyPI has completed its second audit

In 2023 PyPI completed its first security audit, and I am proud to announce that…

7 days ago

Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance

This post will drill deeper into two recent supply chain exploits, targeting users of popular…

3 weeks ago

PowerDNS Master-Slave Configuration with DNSSEC Support

Introduction This guide provides a detailed walk-through for setting up a PowerDNS master-slave configuration on…

3 weeks ago

PayPal Account Verification for Expense Payouts

TLDR ; We are rolling out an important improvement to how payees connect their PayPal…

4 weeks ago

Updated pricing for Organizations, designed for long-term sustainability

TL;DR: We are introducing a new pricing structure for Organizations. We have already been in…

4 weeks ago

Redis ACL – Access Control List

The Redis ACL, short for Access Control List, is the feature that allows certain connections…

1 month ago

This website uses cookies.