# Identity Mesh — May 15, 2026

**Release Date**: May 15, 2026\
**Release Type**: Improvement (Compliance Reporting Accuracy)

------------------------------------------------------------------------

## Overview

This release removes a long-standing false positive from crypto-asset compliance reporting: 3DES was being flagged on certificate templates that don't actually use it. 3DES findings now appear only when key archival is enabled on the certificate template — the only scenario where 3DES is genuinely in use — so you can focus on real key-archival risk instead of filtering noise.

------------------------------------------------------------------------

## Improvements

### 3DES findings limited to certificate templates that actually use it

Most crypto assets were showing 3DES in their non-compliance results even when the algorithm wasn't in use. 3DES only applies when key archival is enabled on the certificate template, but the previous check inferred its presence from an unrelated template setting.

What changed:

- A 3DES non-compliance finding is now reported only when key archival is enabled on the certificate template.

- Certificate templates that don't archive private keys are no longer flagged for 3DES.

You should see far fewer 3DES findings after this release. The findings that remain indicate genuine key-archival risk. No action is needed.
