Microsoft has initiated a critical security hardening phase for Windows Active Directory domain controllers to address CVE-2026-20833, a Kerberos...
Tag Archive for: encryption
4sysops - The online community for sys and AI ops
Windows Secure Boot certificates expire in 2026
Microsoft has started automatically updating Secure Boot certificates on eligible Windows 11 systems with the January 2026 security update....
Outlook cannot open encrypted emails
Microsoft 365 users face a critical bug in Classic Outlook that prevents recipients from opening encrypted emails. In Classic...
Hardware-accelerated BitLocker encryption using SoC crypto engines in Windows 11
Microsoft introduced hardware-accelerated BitLocker to address the performance overhead of disk encryption on modern high-speed NVMe drives. This feature...
Sending encrypted emails with Gmail Client-side Encryption (CSE) to external recipients
On October 2, 2025, Google announced that Gmail Client-side Encryption (CSE) now enables Google Workspace Enterprise Plus users with...
Migrate Certification Authority to Windows Server 2025
In an earlier article, I discussed migrating an Active Directory domain controller to Windows Server 2025. This article explains...
Enable Device Encryption on Windows 11
Device Encryption is a Windows feature that automatically enables BitLocker-based encryption on the system drive and other fixed drives,...
Disable BitLocker on Windows 11
Several reasons exist for wanting to turn off BitLocker on an individual machine or across your network. In Windows...
AI-powered anomaly detection with ManageEngine Ransomware Protection Plus
Cyberattackers are evolving their tactics and developing more sophisticated ransomware. Advanced AI-driven security solutions are needed to provide the...
Recover data from corrupted BitLocker drives with repair-bde and key packages
Activating BitLocker encryption on a drive automatically generates a 48-digit numeric recovery password. This password is crucial if other...
Unlock BitLocker drive from Windows PE with a PowerSell script
BitLocker can pose a significant challenge when multiple PCs need to be booted from an external drive for troubleshooting....
Install Let’s Encrypt certificates on Windows with Certbot and export as PFX
Let's Encrypt offers free certificates that are only valid for 90 days. Because manually renewing them every three months...
Rotate BitLocker recovery passwords, delete used keys from Active Directory
For security reasons, it makes sense to replace the recovery password used to unlock an encrypted drive each time...
New mitigations for CVE-2023-24932 (BlackLotus) in the April update, not yet enabled by default
The remediation of CVE-2023-24932, discovered in May 2023, is taking longer than Microsoft's initial timeline. This flaw allows attackers...
Encrypt and decrypt with Ansible Vault
Ansible Vault allows you to encrypt sensitive data such as passwords, keys, and other secrets rather than storing them...
Forgot BitLocker PIN: recover encrypted drive
Adding a PIN to a TPM protector helps safeguard BitLocker against known attacks. However, this additional security comes with...
Convert certificate format with OpenSSL
OpenSSL is an open-source library and a command-line tool that helps admins and developers perform various cryptographic tasks, such...
Verify digital file signature with SigCheck
SigCheck, part of the SysInternals suite, is a command-line utility offering security features such as verifying the digital file...
Install and use the step-ca certificate authority client
The previous article discussed installing an ACME-compatible certificate authority server. This post explains how to install step-cli (ACME client)...
Step-ca: Running your own Certificate Authority with ACME support
Step-ca is a Certificate Authority (CA) management tool for Windows, Linux, and macOS designed to simplify the process of...


.png)




















