New features, upcoming releases & more | Ascertia Blog

ADSS Server v8.4.2 – New Product Release

Written by Mike Hathaway | Aug 18, 2026, 10:30:00 AM

I’m pleased to announce the release of ADSS Server v8.4.2, the latest regular release update to our flagship PKI and Trust Services platform. This release strengthens certificate authority operations, extends our post‑quantum cryptography support, and continues the modernisation of the Unity Console – reinforcing Ascertia’s position at the forefront of digital trust innovation.

ADSS Server is a full‑featured, modular trust services platform trusted globally by enterprises, government agencies, and trust service providers to deliver certificate authority, digital signing, timestamping, validation, and lifecycle services from one unified platform.

What’s New in v8.4.2

ADSS Server v8.4.2 introduces a set of enhancements that give Certificate Authority operators greater control and assurance, extend our post‑quantum cryptography roadmap, and bring further ePassport services into the modernised Unity Console.

1. Extending Post‑Quantum Cryptography Support with ML‑DSA

ADSS Server has supported post‑quantum cryptography since 2024, and v8.4.2 extends that support further with PKCS#11 integration for ML‑DSA key pair generation and certificate issuance using Thales Luna HSMs.

ML‑DSA (Module‑Lattice‑Based Digital Signature Algorithm) is one of the algorithms standardised by NIST as part of its post‑quantum cryptography programme, designed to remain secure against attacks from both classical and quantum computers. Generating and protecting ML‑DSA keys within a certified hardware security module gives organisations a hardware‑backed root of trust for their post‑quantum certificates, consistent with the assurance levels already expected of classical PKI deployments.

This capability is available today for the ADSS Server CA, with support for additional services and other HSM vendors following in subsequent releases – continuing our commitment to helping customers prepare for a post‑quantum future at their own pace.

2. Greater Control and Compliance with Configurable CRL Template Settings

ADSS Server Local CAs extends configurable profile settings, giving operators fine‑grained control over the extensions included in Certificate Revocation Lists and improving alignment with RFC 5280.

Operators can now configure the Authority Key Identifier, Issuer Alternative Name, and Authority Information Access extensions – including their criticality – directly from CA Manager. Support for the Issuing Distribution Point extension has also been extended to both Full and Partitioned CRLs, with validation in place to help ensure configurations meet CA/Browser Forum and WebTrust requirements.

These changes give Certificate Authority operators the flexibility to tailor CRL content to their specific compliance and operational requirements, without compromising on standards alignment.

3. Continuing Unity Console Modernisation: ePassport SPOC and NPKD Services

As part of the ongoing modernisation of ADSS Server administration, the ePassport SPOC (Single Point of Contact) and NPKD (National Public Key Directory) services are now available in the Unity Console.

This gives operators a more intuitive, integrated experience when managing ePassport trust infrastructure, and lets teams seamlessly switch between consoles as they transition their workflows to the modernised interface.

4. Certificate Serial Number Uniqueness Enforcement – Guaranteed by Design

Certificate serial numbers in ADSS Server have always been generated using a cryptographically secure PRNG (HMacSHA256PRNG‑SP800‑90A), providing a very high degree of collision resistance. With this release, ADSS Server goes a step further: a new uniqueness enforcement check validates each generated serial number before issuance, eliminating even the small residual probability of collision inherent to any random‑generation process. The result is a defense‑in‑depth approach – strong cryptographic randomness backed by deterministic verification.

Why This Matters

Together, these enhancements reflect the priorities we hear most consistently from our customers: confidence that their CA infrastructure is ready for a post‑quantum future, the flexibility to meet evolving compliance requirements, a consistent and modern operator experience, and absolute certainty in the integrity of every certificate issued.

For Certificate Authorities and trust service providers, v8.4.2 means stronger assurance with less operational overhead. For government and ePassport programmes, it means a more unified, modern platform for managing critical identity infrastructure. And for every organisation planning ahead, it means continued confidence that ADSS Server is evolving alongside the threats and standards that shape digital trust.

A Stronger Trust Services Platform from Ascertia

This release reinforces ADSS Server as a trusted, forward‑looking platform for certificate authority and digital trust operations.

With extended post‑quantum cryptography support, more configurable CRL compliance controls, continued Unity Console modernisation, and guaranteed certificate serial number uniqueness, ADSS Server v8.4.2 gives Ascertia an even stronger proposition for customers who depend on our platform to issue, protect, and validate digital trust at scale.

These enhancements support our wider mission: helping governments and organisations establish digital trust in the systems, documents, identities, and transactions that matter most.