Cryptography, TLS, and Key Management

Cryptography, TLS, and Key Management

This guide connects my writing on cryptography and secure communications to the architecture decisions behind it: what TLS protects, where private keys should live, how cloud key control works, and how to plan for post-quantum change.

Understand the protocol and its limits

Protect keys and plan for change

Questions for a key-management review

Identify who can use, administer, rotate, disable, and recover each key. Distinguish key custody from control over the service encrypted by that key. Check how workloads authenticate to the key service, how rotation and recovery are tested, and what audit evidence exists. For long-lived sensitive data, include cryptographic inventory and migration dependencies in post-quantum planning.

The articles explain general architecture principles. Verify current product capabilities and applicable standards against their primary documentation before making implementation decisions.

Related guides: AI governance and risk management · Cloud AI trust boundaries · About the author and editorial policy