Skip to content

TLS & Certificate Insights

Timely analysis. Academy stays evergreen. Changelog stays product-only. Publication dates are the day an article became public.

Featured · Web PKI

Public TLS certificates are now capped at 200 days: what changed in 2026

From 15 March 2026 a newly issued publicly trusted subscriber certificate may be valid for at most 200 days. Existing certificates keep their original expiry.

Published 2026-09-21

Operations & Reliability

Why certificate inventory comes before certificate automation

You cannot renew what you cannot name. Inventory is the first control, not a dashboard decoration.

2026-09-21

TLS Standards

September 15, 2026: the remaining SHA-1 use in public Web PKI reaches its sunset

The CA/Browser Forum sunset for remaining SHA-1 certificate and CRL usage in public Web PKI is 15 September 2026.

2026-09-21

Post-Quantum

Post-quantum HTTPS authentication: what Chromium’s roadmap actually says

Post-quantum key agreement is not the same as post-quantum certificate authentication. Do not conflate the two in a board slide.

2026-09-21

Hosting & Infrastructure

DNS-01 automation without giving away your DNS account: least-privilege patterns

A token that can rewrite MX is the wrong token for ACME. Scope the write to the challenge name.

2026-09-21

SaaS & Custom Domains

How to design TLS for SaaS custom domains at scale

A customer hostname is not a marketing field. It is ownership, DNS, issuance, delivery and renewal.

2026-09-21

ACME

Let’s Encrypt six-day certificates and IP address certificates: what they change

Short-lived and IP-address certificates change operational tempo. They do not change the need to verify what the endpoint serves.

2026-09-21

ACME

ACME Renewal Information (ARI): smarter renewal scheduling explained

ARI lets a CA suggest when to renew so everyone does not hit the same hour. It is not a replacement for inventory.

2026-09-21

Certificate Automation

Why certificate renewal automation fails when deployment is still manual

Issued is not installed. Installed is not served. A CA webhook that says renewed does not prove port 443.

2026-09-21

RSS · Next scheduled drafts stay hidden until they publish.