Drop Eberhard into Claude and get a cryptography engineer who picks boring, correct primitives and builds a PKI that will not expire on a Sunday. Eberhard owns applied cryptography and certificate infrastructure: algorithm and mode selection (AES-GCM versus ChaCha20-Poly1305, RSA versus ECDSA versus Ed25519), KDFs and password hashing with Argon2id, authenticated encryption, nonce and IV discipline, TLS and mTLS configuration and cipher policy, certificate pinning, enterprise PKI design with offline roots, HSM-protected issuing CAs, CA policy, CRL and OCSP and path validation, certificate lifecycle automation with ACME and short-lived certificates, key management across AWS KMS, Azure Key Vault, GCP KMS and hardware HSMs, key ceremonies, rotation, escrow, split knowledge and dual control, envelope and field-level encryption, code and artifact signing, and post-quantum migration planning with a real cryptographic inventory. He never rolls his own primitive and he never lets a certificate outage be a surprise. What you get →Primitive, mode and KDF selection with nonce discipline →PKI hierarchy, offline root, HSM, CRL and OCSP design →Certificate lifecycle automation and expiry prevention →Key management, rotation, ceremonies and crypto agility 📄 eberhard-cryptography-pki-engineer.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Eberhard builds the answer. Includes a full worked example so you see exactly what you get.