Elektrine lite

← Feed

CertKit

certkit@infosec.exchange

<p>Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.</p>

Posts

  • Post #4318540

    Compliance audits ask who touched your certificates, when, and why. CertKit now captures every certificate action with timestamps and user attribution. Importance flags let you cut through routine events to the ones with real consequences. #CertificateManagement #PKI

  • Post #4318539

    PSA: You don&amp;#39;t need a private CA for internal SSL certificates. The CA doesn&amp;#39;t connect to your server. It checks a DNS record. Your server can be completely unreachable from the internet. https://www.certkit.io/blog/private-pki-internal-infrastructure #PKI #ACME

  • Post #4318538

    Apple&amp;#39;s 398-day limit exempts private CAs. Most people stopped reading there. There&amp;#39;s a second Apple requirement: all TLS certs, 825 days max. Safari silently rejects anything longer. No bypass, no details. https://www.certkit.io/blog/apple-doesnt-care-who-signed-your-certificate #PrivatePKI #PKI

  • Post #4318537

    Managing SSL certs for clients? New: managed accounts. An MSP sets up the client&amp;#39;s CertKit account, deploys certs and agents, then hands it over. Client owns it. You keep audited support access. https://www.certkit.io/blog/managed-accounts-for-msps #MSP #SSL

  • Post #4318536

    Let&amp;#39;s Encrypt drops cert lifetimes to 45 days by Feb 2028, a year early. CertKit now supports their TLS Server profile, so you can issue 45-day certs today and test your automation before the deadline. https://www.certkit.io/blog/managed-accounts-for-msps #LetsEncrypt #SSL

  • Post #4318535

    PKI has a term for the leaf-to-root trust chain. It has no term for the series of certs you&amp;#39;ve been renewing for years. Certbot calls it a lineage. Nobody else picked it up. At 47-day lifetimes, naming this correctly starts to matter. https://www.certkit.io/blog/certificate-lineage #PKI #TLS

  • Post #4318534

    Live SSL certificate deployment next week. Not a demo environment. Real setup, discovery through renewal. If something breaks, we fix it. June 16, 11am Central. With Richard Hicks. Free. https://us02web.zoom.us/webinar/register/6417812064399/WN_iBrdj5xmT56lUWG1jrf3ZQ #CertificateManagement #WindowsIT

  • Post #4318533

    Let&amp;#39;s Encrypt is going post-quantum. I&amp;#39;m not worried about quantum computers. The real story in Merkle Tree Certificates: smaller handshakes, transparency built in, and even shorter cert lifetimes. https://www.certkit.io/blog/quantum-is-the-least-interesting-part #SSL #PKI

  • Post #4318532

    One SonicWall. The SSL certificate import API is barely documented and shifts between SonicOS versions. Now repeat for every appliance you run, up to 12x a year. Build it yourself and you maintain it forever. https://www.certkit.io/blog/automating-sonicwall-certificates #SSL

  • Post #4318531

    I spent months telling people not to run their own CA. Today CertKit ships Private PKI. Running a CA is a job, so we took the job. SSL certs for mTLS, IPs, and internal names, root auto-installed on deploy. https://www.certkit.io/blog/certkit-private-pki #PKI

  • Post #4146106

    Let&#39;s Encrypt issued its last client auth cert on July 8. They&#39;re 90-day certs, so the last expire in early October with no renewal behind them. If you run mTLS on public certs, that&#39;s the window. https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing

  • Post #3814106

    A 47-day SSL certificate is not a shorter version of the same job. It is a different job. Once a year, a person can renew it. Eight times a year, they cannot. Issuance was solved. Distribution is the hard part. https://runasradio.com/Shows/Show/1041 #SSL #SysAdmin

  • Post #3785504

    If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. https://www.certkit.io/blog/tls-handshake-explained #TLS #SysAdmin

  • Post #3680235

    CertKit now deploys SSL certificates to Microsoft Exchange, SQL Server, SSRS, and Citrix NetScaler. Exchange is auto-detected. No script editing. Template, certificate, done. https://www.certkit.io/blog/easy-mode-certificate-deployments #SSL #sysadmin

  • Post #3628928

    One SSL cert, three servers. Which one generates the private key? Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job. https://www.certkit.io/blog/ssl-certificate-multiple-servers #SSL #PKI

  • Post #3493690

    The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47. Revocation never worked, so the industry is killing long lifespans instead. @toddhgardner@hachyderm.io broke down the why on RunAs Radio. https://runasradio.com/Shows/Show/1041 #SSL #PKI

  • Post #1311053

    Most “certificate automation” stops at issuance. That’s how you renew a cert and still serve the old one. With the CertKit agent, we can now do all three. Renew certs, deploy files, restart services, verify the correct certs run in production. https://www.certkit.io/blog/certkit-agent #PKI #DevOps

  • Post #1311052

    We found a valid DigiCert certificate on a domain we just purchased, issued to someone we&amp;#39;ve never met. Getting it revoked took 6 emails. 72 hours after confirmed revocation, every browser still trusts it. https://www.certkit.io/blog/bygonessl-happened-to-us #InfoSec #CertificateManagement

  • Post #1311051

    Curious how CertKit works? I made a page for that. https://www.certkit.io/how-it-works

  • Post #1311050

    22,000+ incidents in the Verizon DBIR. Man-in-the-middle? Less than 4%, mostly phishing proxies. Not TLS interception. Forward Secrecy killed &amp;quot;record now, decrypt later.&amp;quot; So what actually compromises your connections? https://www.certkit.io/blog/man-in-the-middle #cybersecurity #TLS

  • Post #1311049

    CertKit Agent 1.6: RRAS support, deploy windows, and agent locking. Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized. https://www.certkit.io/blog/agent-1.6 #CertificateAutomation #WebPKI

  • Post #1311048

    March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029. Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you. https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI

  • Post #1311047

    Certificate management has always been a one-person job. CertKit now supports team access: role-based permissions, SAML SSO, MFA, and a weekly digest to keep the whole org in the loop. https://www.certkit.io/blog/user-management #PKI #infosec

  • Post #1311046

    Your cert renewed. The old one is still serving. LinkedIn renewed 10 days before expiry. It never deployed. Most automation catches &amp;quot;forgot to renew.&amp;quot; Nobody verifies the new cert is what the server is actually sending. https://www.certkit.io/blog/how-to-verify-certificate-renewal #PKI #TLS

  • Post #1311045

    CertKit now supports ACME ARI and 6-day certificates. ARI means the CA tells us when to renew. We check it multiple times a day. Your next mass revocation event? Just another boring Tuesday. Nothing to configure. https://www.certkit.io/blog/acme-ari-and-6-day-certificates #PKI #infosec

  • Post #1311044

    Mass revocation gives you 24 hours and thousands of certs to replace. ARI (RFC 9773) automates it, but only if your ACME client is always running. Certbot uses a cron job. acme.sh has no ARI support. https://www.certkit.io/blog/ari-solves-mass-certificate-revocation #PKI #TLS

  • Post #1311043

    A 2024 PKI survey found organizations averaged 3 certificate outages over 24 months. In almost every case, the certificate renewed fine. Distribution is where it fell apart. https://www.certkit.io/blog/certificate-distribution-is-the-last-mile #PKI #infosec

  • Post #1311042

    Some organizations have a hard requirement: private keys cannot leave the network perimeter. Third-party cert management has always meant violating that policy. The CertKit Local Keystore is the fix. Keys stay on your infrastructure. Full automation still works. www.certkit.io/blog/certkit-keystore #PKI #CertificateManagement

  • Post #1311041

    Let&amp;#39;s Encrypt ran a mass revocation drill on 3 million production certificates in March. No user notifications. They shortened ARI windows to signal an emergency and watched who responded. Most ACME clients never noticed. https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation #PKI #ACME

  • Post #1311040

    CertKit Agent 1.8: Windows Certificate Store, Java Keystore, and RDP auto-detection. We also shipped a retro MS-DOS confirmation dialog on April Fools Day. It is fully keyboard-compatible. https://www.certkit.io/blog/agent-1.8 #CertificateManagement #PKI