Sign in

CertKit SSL Certificate Automation

@certkit.io
27 followers 27 following 92 posts

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates. Learn more at www.certkit.io

PostsRepliesMedia
CertKit SSL Certificate Automation @certkit.io · 8h
"Where is the SSL certificate for examplecom?" is now one search across every client you manage. New in CertKit: cross-collection search, a dashboard with a 90-day renewal timeline, and a read-only API for dashboards and invoices. www.certkit.io/blog/certkit...
certkit.io
CertKit for MSPs: a new dashboard, search everywhere, and the API
Every collection and client on one page, a search that finds any certificate, host, or agent, a new dashboard, and a read-only API for the rest.
000
CertKit SSL Certificate Automation @certkit.io · 29/09/2026
SSTP, DirectAccess, RD Gateway, IIS, Exchange, ADFS. None run an ACME client, and every renewal touches a binding, a restart, or a reboot. Oct 6, Richard Hicks and I automate all of it. Bring the appliance nobody has given you a straight answer on: events.teams.microsoft.com/event/894fa7...
events.teams.microsoft.com
Microsoft Virtual Events Powered by Teams
Microsoft Virtual Events Powered by Teams
000
CertKit SSL Certificate Automation @certkit.io · 28/09/2026
The certificate Common Name was deprecated in 2000. We checked 3 billion certs in CT logs and 96% still have one. Browsers ignore it. GlobalProtect, Cisco Umbrella, NetScaler, and Exchange don't. www.certkit.io/blog/does-a-... #PKI #SSL
certkit.io
Does a TLS Certificate Need a Common Name?
The certificate Common Name has been deprecated for decades, but your load balancer and Exchange connectors might not have gotten the memo.
000
CertKit SSL Certificate Automation @certkit.io · 25/09/2026
Apple's draft policy for Merkle Tree Certificates caps validity at 7 days. Not a shorter X.509. A new post-quantum cert type, validated from periodic out-of-band client updates, so it only has to outlive the update cycle. 7 days costs nothing when nothing human renews it. #PKI
020
CertKit SSL Certificate Automation @certkit.io · 23/09/2026
Some jerk got an SSL certificate for a subdomain we had forgotten about, and Google told us before our own CT log tool did. Now CertKit watches the log. You get an email when a certificate shows up for a name it has never seen on your domain. www.certkit.io/blog/ct-alerts
certkit.io
CT alerts: know when someone gets a certificate for your domains
CertKit now watches certificate transparency logs for your domains and emails you when a certificate appears that you have never seen before.
111
CertKit SSL Certificate Automation @certkit.io · 22/09/2026
Your once-a-year SSL renewal becomes a five-times-a-year renewal on March 15, when public cert lifetimes drop from 200 days to 100. At 47 days, twelve. Oct 6, live with Richard Hicks on automating renewal for Windows servers, VPN, and appliances. Free: events.teams.microsoft.com/event/894fa7...
events.teams.microsoft.com
Microsoft Virtual Events Powered by Teams
Microsoft Virtual Events Powered by Teams
000
CertKit SSL Certificate Automation @certkit.io · 21/09/2026
Hey. we can help.
000
CertKit SSL Certificate Automation @certkit.io · 21/09/2026
We're in the Japanese celebrity gossip site business now. A DNS record we forgot for ten years pointed at an IP we gave up. Some jerk got the IP, a Let's Encrypt cert, and a spam site The cert sat in our own CT tool the whole time. www.certkit.io/blog/danglin...
certkit.io
How a ten-year-old dangling DNS record handed one of our subdomains to spammers
We forgot a DNS record for ten years. Someone else got the IP, a certificate, and our subdomain. How dangling DNS becomes a subdomain takeover.
010
CertKit SSL Certificate Automation @certkit.io · 03/09/2026
Cloud SSL certificate monitoring only sees what the internet sees. Your intranet pages expire too, but they don't warn anyone first. CertKit agents now monitor SSL certificates inside your network, and judge trust from the host's own trust store. www.certkit.io/blog/certifi... #PKI #sysadmin
certkit.io
Certificate monitoring for your intranet hosts
CertKit agents now monitor TLS endpoints inside your network, judge trust from the host's trust store, and re-check hosts the moment a certificate deploys.
000
CertKit SSL Certificate Automation @certkit.io · 01/09/2026
Maybe we can help. What are the two systems?
000
CertKit SSL Certificate Automation @certkit.io · 24/08/2026
I searched our own domain in the public certificate transparency logs. Three dev servers and four vendors, named. Nobody scanned us. We published it ourselves by getting SSL certificates. www.certkit.io/blog/somebod... #PKI
certkit.io
Somebody's been keeping a list of your certificates
There is a permanent public record of every certificate ever issued for your domain. You never agreed to it and you can't opt out. I read ours, and it names our dev servers and most of our vendors.
000
CertKit SSL Certificate Automation @certkit.io · 18/08/2026
You didn't turn on the TLS key exchanges the IETF just banned. They shipped that way. nginx, Apache and Windows Server enable RSA key exchange by default. RFC 10015 says MUST NOT. www.certkit.io/blog/tls-1-2... #TLS
certkit.io
TLS 1.2 isn't end of life, but it will be soon
Two RFCs in July took away three of TLS 1.2's key exchange methods and its entire future. The banned ones ship enabled by default in nginx, Apache, and Windows Server, which means you are probably sti...
000
CertKit SSL Certificate Automation @certkit.io · 30/07/2026
I spent months telling people not to run their own certificate authority. Today CertKit ships Private PKI. Running a CA is a job, so we took the job. Internal SSL certs that issue, renew, and get trusted automatically. www.certkit.io/blog/certkit... #PKI
certkit.io
CertKit Private PKI: A private certificate authority without running one yourself
I spent months telling you not to run your own certificate authority. Today CertKit ships Private PKI. Both things are true, because the job was the problem, and we took the job.
000
CertKit SSL Certificate Automation @certkit.io · 29/07/2026
Nice! good solution. We built an integration to push certificates into Netscalers via their CLI.
000
CertKit SSL Certificate Automation @certkit.io · 28/07/2026
Wow, certificate updates can suck. It's going to get more frequent as lifetimes shorten. Maybe we can help.
000
CertKit SSL Certificate Automation @certkit.io · 27/07/2026
Hey there. I might just have something for you at CertKit.io
000
CertKit SSL Certificate Automation @certkit.io · 27/07/2026
Let's Encrypt issued its last client auth cert on July 8. They're 90-day certs, so the last expire in early October with no renewal behind them. If you run mTLS on public certs, that's the window. www.certkit.io/blog/public-...
certkit.io
Public mTLS client-auth certificates stop renewing in October
Chrome's root program is pulling mTLS client authentication out of the public web PKI. Let's Encrypt got there first, and the last client certificates they issued expire in early October.
000
CertKit SSL Certificate Automation @certkit.io · 20/07/2026
The internal box that you set up for a pilot that someone became a critical part of the system and takes everything down :)
110
CertKit SSL Certificate Automation @certkit.io · 14/07/2026
A 47-day SSL certificate is not a shorter version of the same job. It is a different job. Once a year, a person can renew it. Eight times a year, they cannot. Issuance was solved. Distribution is the hard part. runasradio.com/Shows/Show/1... #SSL #SysAdmin
runasradio.com
47 Day Certificates with Todd Gardner
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last o...
000
CertKit SSL Certificate Automation @certkit.io · 13/07/2026
If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. www.certkit.io/blog/tls-han... #TLS #SysAdmin
certkit.io
How the TLS handshake works, and why half of it is gone
Every HTTPS connection starts with a TLS handshake. Most explanations walk the steps without telling you why they exist, or why half the steps you learned no longer happen. The modern handshake is sho...
000
CertKit SSL Certificate Automation @certkit.io · 08/07/2026
CertKit now deploys SSL certificates to Microsoft Exchange, SQL Server, SSRS, and Citrix NetScaler. Exchange is auto-detected. Pick a template, pick a certificate, done. www.certkit.io/blog/easy-mo... #SSL #sysadmin
certkit.io
Certificate deployments just got an easy mode
The old deployment flow expected you to know certificate formats, store locations, and your way around a script editor. The new one asks for a template, a name, and a certificate. That's it.
000
CertKit SSL Certificate Automation @certkit.io · 07/07/2026
Why are SSL certificates dropping to 47 days? Because revocation is broken. OCSP fails open. Revocation lists go stale. A stolen certificate stays trusted too long. Short lifespans are the industry's workaround. runasradio.com/Shows/Show/1... #SSL #InfoSec
runasradio.com
47 Day Certificates with Todd Gardner
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last o...
000
CertKit SSL Certificate Automation @certkit.io · 06/07/2026
We're building something so you don't need to care about this anymore. certkit.io
000
CertKit SSL Certificate Automation @certkit.io · 06/07/2026
One SSL cert, three servers. Which one generates the private key? Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job. www.certkit.io/blog/ssl-cer... #SSL #PKI
certkit.io
One SSL certificate on multiple servers
Generating the private key on the server it protects is the textbook answer. Then someone asks for a wildcard, or a second server, and the textbook doesn't have a chapter for that.
000
CertKit SSL Certificate Automation @certkit.io · 01/07/2026
One SonicWall. The SSL certificate import API is barely documented and shifts between SonicOS versions. Now repeat for every appliance you run, up to 12x a year. Build it yourself and you maintain it forever. www.certkit.io/blog/automat... #SSL
certkit.io
Automating SonicWall Certificate Deployment with the SonicOS API
Certificate lifetimes are shrinking to 47 days. Manually updating SSL certificates through the SonicWall Administration UI is no longer an option. We automate the process, but SonicOS doesn't make it ...
000
CertKit SSL Certificate Automation @certkit.io · 30/06/2026
The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47. Revocation never worked, so the industry is killing long lifespans instead. @toddhgardner.com broke down the why on RunAs Radio. runasradio.com/Shows/Show/1... #SSL #PKI
runasradio.com
47 Day Certificates with Todd Gardner
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last o...
000
CertKit SSL Certificate Automation @certkit.io · 29/06/2026
Let's Encrypt is going post-quantum. I'm not worried about quantum computers. The real story in Merkle Tree Certificates: smaller handshakes, transparency built in, and even shorter cert lifetimes. www.certkit.io/blog/quantum... #SSL #PKI
certkit.io
Quantum is the least interesting part of quantum certificates
Let's Encrypt just committed to Merkle Tree Certificates for a post-quantum web. I don't think quantum computers are close. The plan is still worth your attention, just not for the reason the headline...
000
Reposted by CertKit SSL Certificate Automation
Richard Campbell @richcampbell.bsky.social · 22/06/2026
The problem with SSL certificates is revocation mechanisms - they just don't work. So the industry has responded by shortening lifespans, ultimately to only 47 days. @ToddHGardner.com talks on RunAs Radio at runasradio.com/Shows/Show/1... about automating routine renewal of certificates!
031
CertKit SSL Certificate Automation @certkit.io · 11/06/2026
Live SSL certificate deployment next week. Real setup, not a polished demo. If something breaks, we fix it on air. June 16, 11am Central. With Richard Hicks. us02web.zoom.us/webinar/regi... #CertificateManagement #WindowsIT
us02web.zoom.us
Welcome! You are invited to join a webinar: Certificate Automation in Practice: A Technical Deep Dive for Windows IT. After registering, you will receive a confirmation email about joining the webinar...
with Richard Hicks and Todd Gardner June 16 | 11:00am Central | 60 minutes | Free The first question most Windows IT teams have after deciding to automate certificate management isn't "should we do t...
010
CertKit SSL Certificate Automation @certkit.io · 08/06/2026
PKI has a term for the leaf-to-root trust chain. It has no term for the series of certs you've been renewing for years. Certbot calls it a lineage. Nobody else picked it up. At 47-day lifetimes, naming this correctly starts to matter. www.certkit.io/blog/certifi... #PKI #TLS
certkit.io
Certificate lineage: the concept your tools already use but nobody named
PKI has precise terminology for almost everything. The one thing it never named is the series of certificates you've been renewing for years. Here's what it is, why it matters now, and why your tools ...
000
CertKit SSL Certificate Automation @certkit.io · 04/06/2026
Let's Encrypt drops cert lifetimes to 45 days by Feb 2028, a year early. CertKit now supports their TLS Server profile, so you can issue 45-day certs today and test your automation before the deadline. www.certkit.io/blog/managed... #LetsEncrypt #SSL
certkit.io
Managed accounts for MSPs, plus 45-day certificates you can use today
MSPs can now stand up fully-managed CertKit accounts for their clients, deploy certificates and agents, then hand over the keys. We also added support for Let's Encrypt's TLS Server profile, so you ca...
030
CertKit SSL Certificate Automation @certkit.io · 03/06/2026
Managing SSL certs for clients? New: managed accounts. An MSP sets up the client's CertKit account, deploys certs and agents, then hands it over. Client owns it. You keep audited support access. www.certkit.io/blog/managed... #MSP #SSL
certkit.io
Managed accounts for MSPs, plus 45-day certificates you can use today
MSPs can now stand up fully-managed CertKit accounts for their clients, deploy certificates and agents, then hand over the keys. We also added support for Let's Encrypt's TLS Server profile, so you ca...
020
CertKit SSL Certificate Automation @certkit.io · 01/06/2026
Apple's 398-day limit exempts private CAs. Most people stopped reading there. There's a second Apple requirement: all TLS certs, 825 days max. Safari silently rejects anything longer. No bypass, no details. www.certkit.io/blog/apple-d... #PrivatePKI #PKI
certkit.io
Apple doesn't care who signed your certificate
Running a private CA to escape the public cert treadmill makes sense. Apple still enforces an 825-day validity limit in Safari on every TLS certificate, no matter who issued it.
020
CertKit SSL Certificate Automation @certkit.io · 26/05/2026
PSA: You don't need a private CA for internal SSL certificates. DNS-01 ACME challenges let you issue publicly trusted certs for servers that never touch the internet. No root cert distribution. No click-through warnings. www.certkit.io/blog/private... #PKI #SSL
certkit.io
You probably don't need private PKI for internal infrastructure
Most teams assume internal infrastructure needs a private CA. It doesn't - and skipping it saves you from a maintenance burden that never fully works anyway.
000
CertKit SSL Certificate Automation @certkit.io · 25/05/2026
We can help you centralize all your renewal and get free certificates from Google or Lets Encrypt. Imagine never buying a certificate again. 😎
000
CertKit SSL Certificate Automation @certkit.io · 20/05/2026
When your auditor asks what happened to your certificates last Tuesday, you need an answer. CertKit now logs every action in your certificate lifecycle: issuances, renewals, revocations, deployments, agent approvals. With importance flags so you can find what matters. #CertificateManagement #PKI
000
CertKit SSL Certificate Automation @certkit.io · 18/05/2026
Not yet
000
CertKit SSL Certificate Automation @certkit.io · 18/05/2026
Burn it all down and use CertKit instead :p
100
CertKit SSL Certificate Automation @certkit.io · 08/05/2026
F5 LTM. Palo Alto. Azure Key Vault. Exchange. We shipped a deployment scripting template library for all of them. Pick your target, configure your variables, and CertKit pushes the certificate to your infrastructure. www.certkit.io/blog/deploym... #CertificateManagement #PKI
certkit.io
Remote deployment scripting
CertKit now ships centrally managed deployment scripts that push certificates directly to appliances, cloud platforms, and custom infrastructure, with a template library and encrypted variable storage...
010
CertKit SSL Certificate Automation @certkit.io · 05/05/2026
50 SSL certificates managed manually today means roughly 50 renewals a year. Same team, same certs, in 2029: 400. The CA/Browser Forum's new lifetime schedule doesn't just change how often you renew. It changes the job. www.certkit.io/blog/shrinki... #PKI #SSL
certkit.io
Certificate lifetimes are shrinking.
Certificate validity is dropping from 398 days to 47 days by 2029. Here is the canonical schedule, what's driving it, and what it does to your renewal workload.
010
CertKit SSL Certificate Automation @certkit.io · 29/04/2026
Your VPN, RRAS, and IIS all need certificates. None of them can run ACME. Most teams patch this with scripts and hope. May 26, Richard Hicks and I are doing 30 minutes on what actually works. www.certkit.io/blog/webinar... #WindowsServer #SSL
certkit.io
Live Webinar: certificate automation for Windows infrastructure
On May 26, I'm doing a 30-minute live session with Richard Hicks on what actually works for SSL certificate automation in Windows environments. VPNs, IIS, RRAS, vendor appliances, the endpoints that c...
000
CertKit SSL Certificate Automation @certkit.io · 27/04/2026
Philip Greenspun's Tenth Rule: any complicated C program contains a bad implementation of half of Lisp. Certificate automation has the same problem. Todd named it. www.certkit.io/blog/todds-t... #CertificateManagement #SysAdmin
certkit.io
Todd's Tenth Rule of certificate automation
Any sufficiently complicated SSL certificate renewal system contains an ad hoc, informally-specified, bug-ridden, slow implementation of half a certificate lifecycle manager. I'm taking credit for thi...
010
CertKit SSL Certificate Automation @certkit.io · 25/04/2026
To you, it looks like your proposed inversion of control.
100
CertKit SSL Certificate Automation @certkit.io · 25/04/2026
You add a little configuration so we know how to reset your software to pick up the new certs.
100
CertKit SSL Certificate Automation @certkit.io · 25/04/2026
Your systems poll is periodically for changes, and pull new certs when they are ready.
100
CertKit SSL Certificate Automation @certkit.io · 25/04/2026
We act as the acme client, so you don’t hold any of this directly. We manage your credentials, generate your certs, handle the renewals.
100
CertKit SSL Certificate Automation @certkit.io · 25/04/2026
Interesting, this would be some major shifts in how things work. Certkit kinda acts as a middleman that does some of this though.
100
CertKit SSL Certificate Automation @certkit.io · 24/04/2026
Safely distributing certs to where they are needed is the next big challenge, and we're working on that.
100
CertKit SSL Certificate Automation @certkit.io · 24/04/2026
Lots of stuff is changing, and it's going to cause a lot of disruption. It's also an opportunity to make things easier. Paying for certificates is an outdated concept. ACME is going to get better, and you can centralize it instead of running it everywhere.
100
CertKit SSL Certificate Automation @certkit.io · 22/04/2026
Managing SSL certs across dozens of servers? You shouldn't have to configure each one by hand. New in CertKit: copy and link agent configs across your fleet, search and filter your monitors, plus our first GDPR Data Processing Agreement. www.certkit.io/blog/shared-... #CertificateManagement #SSL
certkit.io
Shared agent configs, monitor search, and a GDPR policy
Copy and share agent configurations across your fleet, search and sort your monitored domains, and our first official Data Processing Agreement for GDPR compliance.
000