Elektrine lite

← Feed

CertKit

certkit@infosec.exchange

<p>Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.</p>

Posts

  • View post

    Your once-a-year SSL renewal becomes a five-times-a-year renewal on March 15, when public cert lifetimes drop from 200 days to 100. At 47 days, twelve. Oct 6, live with Richard Hicks on automating renewal for Windows servers, VPN, and appliances. Free: https://events.teams.microsoft.com/event/894fa781-9bbd-4eae-9371-86319c13cb08@3b2fb46b-9bbe-41a2-a6fe-a54cbca02865

  • View post

    Compliance audits ask who touched your certificates, when, and why. CertKit now captures every certificate action with timestamps and user attribution. Importance flags let you cut through routine events to the ones with real consequences. #CertificateManagement #PKI

  • View post

    PSA: You don&amp;#39;t need a private CA for internal SSL certificates. The CA doesn&amp;#39;t connect to your server. It checks a DNS record. Your server can be completely unreachable from the internet. https://www.certkit.io/blog/private-pki-internal-infrastructure #PKI #ACME

  • View post

    Apple&amp;#39;s 398-day limit exempts private CAs. Most people stopped reading there. There&amp;#39;s a second Apple requirement: all TLS certs, 825 days max. Safari silently rejects anything longer. No bypass, no details. https://www.certkit.io/blog/apple-doesnt-care-who-signed-your-certificate #PrivatePKI #PKI

  • View post

    Managing SSL certs for clients? New: managed accounts. An MSP sets up the client&amp;#39;s CertKit account, deploys certs and agents, then hands it over. Client owns it. You keep audited support access. https://www.certkit.io/blog/managed-accounts-for-msps #MSP #SSL

  • View post

    Let&amp;#39;s Encrypt drops cert lifetimes to 45 days by Feb 2028, a year early. CertKit now supports their TLS Server profile, so you can issue 45-day certs today and test your automation before the deadline. https://www.certkit.io/blog/managed-accounts-for-msps #LetsEncrypt #SSL

  • View post

    PKI has a term for the leaf-to-root trust chain. It has no term for the series of certs you&amp;#39;ve been renewing for years. Certbot calls it a lineage. Nobody else picked it up. At 47-day lifetimes, naming this correctly starts to matter. https://www.certkit.io/blog/certificate-lineage #PKI #TLS

  • View post

    Live SSL certificate deployment next week. Not a demo environment. Real setup, discovery through renewal. If something breaks, we fix it. June 16, 11am Central. With Richard Hicks. Free. https://us02web.zoom.us/webinar/register/6417812064399/WN_iBrdj5xmT56lUWG1jrf3ZQ #CertificateManagement #WindowsIT

  • View post

    Let&amp;#39;s Encrypt is going post-quantum. I&amp;#39;m not worried about quantum computers. The real story in Merkle Tree Certificates: smaller handshakes, transparency built in, and even shorter cert lifetimes. https://www.certkit.io/blog/quantum-is-the-least-interesting-part #SSL #PKI

  • View post

    One SonicWall. The SSL certificate import API is barely documented and shifts between SonicOS versions. Now repeat for every appliance you run, up to 12x a year. Build it yourself and you maintain it forever. https://www.certkit.io/blog/automating-sonicwall-certificates #SSL

  • View post

    I spent months telling people not to run their own CA. Today CertKit ships Private PKI. Running a CA is a job, so we took the job. SSL certs for mTLS, IPs, and internal names, root auto-installed on deploy. https://www.certkit.io/blog/certkit-private-pki #PKI

  • View post

    Let&#39;s Encrypt issued its last client auth cert on July 8. They&#39;re 90-day certs, so the last expire in early October with no renewal behind them. If you run mTLS on public certs, that&#39;s the window. https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing

  • View post

    A 47-day SSL certificate is not a shorter version of the same job. It is a different job. Once a year, a person can renew it. Eight times a year, they cannot. Issuance was solved. Distribution is the hard part. https://runasradio.com/Shows/Show/1041 #SSL #SysAdmin

  • View post

    If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. https://www.certkit.io/blog/tls-handshake-explained #TLS #SysAdmin

  • View post

    CertKit now deploys SSL certificates to Microsoft Exchange, SQL Server, SSRS, and Citrix NetScaler. Exchange is auto-detected. No script editing. Template, certificate, done. https://www.certkit.io/blog/easy-mode-certificate-deployments #SSL #sysadmin

  • View post

    One SSL cert, three servers. Which one generates the private key? Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job. https://www.certkit.io/blog/ssl-certificate-multiple-servers #SSL #PKI

  • View post

    The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47. Revocation never worked, so the industry is killing long lifespans instead. @toddhgardner@hachyderm.io broke down the why on RunAs Radio. https://runasradio.com/Shows/Show/1041 #SSL #PKI

  • View post

    Most “certificate automation” stops at issuance. That’s how you renew a cert and still serve the old one. With the CertKit agent, we can now do all three. Renew certs, deploy files, restart services, verify the correct certs run in production. https://www.certkit.io/blog/certkit-agent #PKI #DevOps

  • View post

    We found a valid DigiCert certificate on a domain we just purchased, issued to someone we&amp;#39;ve never met. Getting it revoked took 6 emails. 72 hours after confirmed revocation, every browser still trusts it. https://www.certkit.io/blog/bygonessl-happened-to-us #InfoSec #CertificateManagement

  • View post

    Curious how CertKit works? I made a page for that. https://www.certkit.io/how-it-works

  • View post

    22,000+ incidents in the Verizon DBIR. Man-in-the-middle? Less than 4%, mostly phishing proxies. Not TLS interception. Forward Secrecy killed &amp;quot;record now, decrypt later.&amp;quot; So what actually compromises your connections? https://www.certkit.io/blog/man-in-the-middle #cybersecurity #TLS

  • View post

    CertKit Agent 1.6: RRAS support, deploy windows, and agent locking. Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized. https://www.certkit.io/blog/agent-1.6 #CertificateAutomation #WebPKI

  • View post

    March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029. Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you. https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI

  • View post

    Certificate management has always been a one-person job. CertKit now supports team access: role-based permissions, SAML SSO, MFA, and a weekly digest to keep the whole org in the loop. https://www.certkit.io/blog/user-management #PKI #infosec

  • View post

    Your cert renewed. The old one is still serving. LinkedIn renewed 10 days before expiry. It never deployed. Most automation catches &amp;quot;forgot to renew.&amp;quot; Nobody verifies the new cert is what the server is actually sending. https://www.certkit.io/blog/how-to-verify-certificate-renewal #PKI #TLS

  • View post

    CertKit now supports ACME ARI and 6-day certificates. ARI means the CA tells us when to renew. We check it multiple times a day. Your next mass revocation event? Just another boring Tuesday. Nothing to configure. https://www.certkit.io/blog/acme-ari-and-6-day-certificates #PKI #infosec

  • View post

    Mass revocation gives you 24 hours and thousands of certs to replace. ARI (RFC 9773) automates it, but only if your ACME client is always running. Certbot uses a cron job. acme.sh has no ARI support. https://www.certkit.io/blog/ari-solves-mass-certificate-revocation #PKI #TLS

  • View post

    A 2024 PKI survey found organizations averaged 3 certificate outages over 24 months. In almost every case, the certificate renewed fine. Distribution is where it fell apart. https://www.certkit.io/blog/certificate-distribution-is-the-last-mile #PKI #infosec

  • View post

    Some organizations have a hard requirement: private keys cannot leave the network perimeter. Third-party cert management has always meant violating that policy. The CertKit Local Keystore is the fix. Keys stay on your infrastructure. Full automation still works. www.certkit.io/blog/certkit-keystore #PKI #CertificateManagement

  • View post

    Let&amp;#39;s Encrypt ran a mass revocation drill on 3 million production certificates in March. No user notifications. They shortened ARI windows to signal an emergency and watched who responded. Most ACME clients never noticed. https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation #PKI #ACME