Somewhere in your company
there is a calendar reminder.
Renew the certificate.
Once a year.
One person.
A half day of copying files
to the right servers
and hoping nothing was missed.
That reminder has a deadline of its own.
The browser makers
and the certificate authorities
agreed in 2025
to cut how long
a public TLS certificate can live.
Two hundred days,
from this year.
One hundred,
from March 2027.
Forty seven,
from March 2029.
And the proof
that you control the domain
can be reused
for only ten days
by the end of it.
Do the arithmetic
on the reminder.
Eight renewals a year,
at least,
per certificate.
Multiply by every domain,
every load balancer,
every appliance
with its own web page
that somebody set up by hand
in 2019.
Manual renewal
does not get harder.
It stops being possible.
The reason is sound.
A certificate that lives for a year
stays trusted for a year
after its key leaks
or its owner changes,
because revocation
has never really worked.
Short lives make the mistake
expire on its own.
But it moves the risk.
The danger used to be
a stolen key.
Now it is an expired one,
on a Sunday,
because one renewal job
quietly failed
and nobody was watching.
So automate the whole path,
not just the request.
Issue,
install,
reload the thing that serves it,
and check from outside
that the new one is live.
Use the protocol made for this
and a client that runs
on its own schedule.
Renew at a third of the lifetime left,
so a failure gives you weeks,
not hours.
Monitor expiry from outside your network,
the way a customer's browser would,
and page a person
long before the date.
Then find the stragglers.
The device
that only takes an upload
through a web form.
The vendor
who emails you a file.
The certificate pinned in a mobile app.
Those are this year's work,
while you still have
two hundred days to do it.
Anything you renew by hand today
is something you will
fail to renew
in 2029.
– Serguey Asael Shinder
Top comments (0)