CertKit
certkit@infosec.exchange
<p>Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.</p>
Posts
-
View post
Your once-a-year SSL renewal becomes a five-times-a-year renewal on March 15, when public cert lifetimes drop from 200 days to 100. At 47 days, twelve. Oct 6, live with Richard Hicks on automating renewal for Windows servers, VPN, and appliances. Free: https://events.teams.microsoft.com/event/894fa781-9bbd-4eae-9371-86319c13cb08@3b2fb46b-9bbe-41a2-a6fe-a54cbca02865
-
View post
Compliance audits ask who touched your certificates, when, and why. CertKit now captures every certificate action with timestamps and user attribution. Importance flags let you cut through routine events to the ones with real consequences. #CertificateManagement #PKI
-
View post
PSA: You don&#39;t need a private CA for internal SSL certificates. The CA doesn&#39;t connect to your server. It checks a DNS record. Your server can be completely unreachable from the internet. https://www.certkit.io/blog/private-pki-internal-infrastructure #PKI #ACME
-
View post
Apple&#39;s 398-day limit exempts private CAs. Most people stopped reading there. There&#39;s a second Apple requirement: all TLS certs, 825 days max. Safari silently rejects anything longer. No bypass, no details. https://www.certkit.io/blog/apple-doesnt-care-who-signed-your-certificate #PrivatePKI #PKI
-
View post
Managing SSL certs for clients? New: managed accounts. An MSP sets up the client&#39;s CertKit account, deploys certs and agents, then hands it over. Client owns it. You keep audited support access. https://www.certkit.io/blog/managed-accounts-for-msps #MSP #SSL
-
View post
Let&#39;s Encrypt drops cert lifetimes to 45 days by Feb 2028, a year early. CertKit now supports their TLS Server profile, so you can issue 45-day certs today and test your automation before the deadline. https://www.certkit.io/blog/managed-accounts-for-msps #LetsEncrypt #SSL
-
View post
PKI has a term for the leaf-to-root trust chain. It has no term for the series of certs you&#39;ve been renewing for years. Certbot calls it a lineage. Nobody else picked it up. At 47-day lifetimes, naming this correctly starts to matter. https://www.certkit.io/blog/certificate-lineage #PKI #TLS
-
View post
Live SSL certificate deployment next week. Not a demo environment. Real setup, discovery through renewal. If something breaks, we fix it. June 16, 11am Central. With Richard Hicks. Free. https://us02web.zoom.us/webinar/register/6417812064399/WN_iBrdj5xmT56lUWG1jrf3ZQ #CertificateManagement #WindowsIT
-
View post
Let&#39;s Encrypt is going post-quantum. I&#39;m not worried about quantum computers. The real story in Merkle Tree Certificates: smaller handshakes, transparency built in, and even shorter cert lifetimes. https://www.certkit.io/blog/quantum-is-the-least-interesting-part #SSL #PKI
-
View post
One SonicWall. The SSL certificate import API is barely documented and shifts between SonicOS versions. Now repeat for every appliance you run, up to 12x a year. Build it yourself and you maintain it forever. https://www.certkit.io/blog/automating-sonicwall-certificates #SSL
-
View post
I spent months telling people not to run their own CA. Today CertKit ships Private PKI. Running a CA is a job, so we took the job. SSL certs for mTLS, IPs, and internal names, root auto-installed on deploy. https://www.certkit.io/blog/certkit-private-pki #PKI
-
View post
Let's Encrypt issued its last client auth cert on July 8. They're 90-day certs, so the last expire in early October with no renewal behind them. If you run mTLS on public certs, that's the window. https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing
-
View post
A 47-day SSL certificate is not a shorter version of the same job. It is a different job. Once a year, a person can renew it. Eight times a year, they cannot. Issuance was solved. Distribution is the hard part. https://runasradio.com/Shows/Show/1041 #SSL #SysAdmin
-
View post
If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. https://www.certkit.io/blog/tls-handshake-explained #TLS #SysAdmin
-
View post
CertKit now deploys SSL certificates to Microsoft Exchange, SQL Server, SSRS, and Citrix NetScaler. Exchange is auto-detected. No script editing. Template, certificate, done. https://www.certkit.io/blog/easy-mode-certificate-deployments #SSL #sysadmin
-
View post
One SSL cert, three servers. Which one generates the private key? Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job. https://www.certkit.io/blog/ssl-certificate-multiple-servers #SSL #PKI
-
View post
The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47. Revocation never worked, so the industry is killing long lifespans instead. @toddhgardner@hachyderm.io broke down the why on RunAs Radio. https://runasradio.com/Shows/Show/1041 #SSL #PKI
-
View post
Most “certificate automation” stops at issuance. That’s how you renew a cert and still serve the old one. With the CertKit agent, we can now do all three. Renew certs, deploy files, restart services, verify the correct certs run in production. https://www.certkit.io/blog/certkit-agent #PKI #DevOps
-
View post
We found a valid DigiCert certificate on a domain we just purchased, issued to someone we&#39;ve never met. Getting it revoked took 6 emails. 72 hours after confirmed revocation, every browser still trusts it. https://www.certkit.io/blog/bygonessl-happened-to-us #InfoSec #CertificateManagement
-
View post
Curious how CertKit works? I made a page for that. https://www.certkit.io/how-it-works
-
View post
22,000+ incidents in the Verizon DBIR. Man-in-the-middle? Less than 4%, mostly phishing proxies. Not TLS interception. Forward Secrecy killed &quot;record now, decrypt later.&quot; So what actually compromises your connections? https://www.certkit.io/blog/man-in-the-middle #cybersecurity #TLS
-
View post
CertKit Agent 1.6: RRAS support, deploy windows, and agent locking. Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized. https://www.certkit.io/blog/agent-1.6 #CertificateAutomation #WebPKI
-
View post
March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029. Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you. https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI
-
View post
Certificate management has always been a one-person job. CertKit now supports team access: role-based permissions, SAML SSO, MFA, and a weekly digest to keep the whole org in the loop. https://www.certkit.io/blog/user-management #PKI #infosec
-
View post
Your cert renewed. The old one is still serving. LinkedIn renewed 10 days before expiry. It never deployed. Most automation catches &quot;forgot to renew.&quot; Nobody verifies the new cert is what the server is actually sending. https://www.certkit.io/blog/how-to-verify-certificate-renewal #PKI #TLS
-
View post
CertKit now supports ACME ARI and 6-day certificates. ARI means the CA tells us when to renew. We check it multiple times a day. Your next mass revocation event? Just another boring Tuesday. Nothing to configure. https://www.certkit.io/blog/acme-ari-and-6-day-certificates #PKI #infosec
-
View post
Mass revocation gives you 24 hours and thousands of certs to replace. ARI (RFC 9773) automates it, but only if your ACME client is always running. Certbot uses a cron job. acme.sh has no ARI support. https://www.certkit.io/blog/ari-solves-mass-certificate-revocation #PKI #TLS
-
View post
A 2024 PKI survey found organizations averaged 3 certificate outages over 24 months. In almost every case, the certificate renewed fine. Distribution is where it fell apart. https://www.certkit.io/blog/certificate-distribution-is-the-last-mile #PKI #infosec
-
View post
Some organizations have a hard requirement: private keys cannot leave the network perimeter. Third-party cert management has always meant violating that policy. The CertKit Local Keystore is the fix. Keys stay on your infrastructure. Full automation still works. www.certkit.io/blog/certkit-keystore #PKI #CertificateManagement
-
View post
Let&#39;s Encrypt ran a mass revocation drill on 3 million production certificates in March. No user notifications. They shortened ARI windows to signal an emergency and watched who responded. Most ACME clients never noticed. https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation #PKI #ACME