home.social

#certificatemanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #certificatemanagement, aggregated by home.social.

fetched live
  1. A new ranking compares 10 tools for issuing and managing website certificates, with DigiCert first at 9.1 and Keyfactor second at 9.0.

    Automation from renewal through installation accounts for 30% of the score.

    The ranking draws on research, public pricing information and professional reports; it did not include lab testing.

    The article notes that public website certificates are expected to have a ma…

    en.hacks.gr/digicert-proti-se-

    #DigiCert #Keyfactor #CertificateManagement #CertificateAutomation

  2. Live SSL certificate deployment next week. Not a demo environment. Real setup, discovery through renewal. If something breaks, we fix it.

    June 16, 11am Central. With Richard Hicks. Free.

    us02web.zoom.us/webinar/regist

    #CertificateManagement #WindowsIT

  3. Compliance audits ask who touched your certificates, when, and why.

    CertKit now captures every certificate action with timestamps and user attribution. Importance flags let you cut through routine events to the ones with real consequences.

    #CertificateManagement #PKI

  4. Certificate distribution has always been the messy part. Custom scripts, shared drives, passwords in plaintext somewhere.

    We shipped deployment scripting with a template library for F5, Palo Alto, Azure, Exchange, and more. Variables encrypted, never on disk.

    certkit.io/blog/deployment-scr

    #CertificateManagement #PKI

  5. Todd's Tenth Rule: any sufficiently complicated SSL certificate script contains a bad implementation of half a certificate lifecycle manager.

    Named the pattern. Here's how it happens.

    certkit.io/blog/todds-tenth-ru

    #CertificateManagement #PKI

  6. New in CertKit: copy and link agent configs across your fleet instead of configuring each server individually. Also added search and grouping for monitored domains, plus our first GDPR Data Processing Agreement.

    certkit.io/blog/shared-configs

    #CertificateManagement #SSL

  7. CertKit 1.9: push agent updates from the dashboard, no more logging into every server. Plus Google Trust Store as a second ACME issuer alongside Let's Encrypt.

    certkit.io/blog/agent-1.9

    #CertificateManagement #SSL

  8. CertKit is out of beta.

    600 signups. Real production deployments. A Keystore for keeping private keys on-prem. RDP and RRAS support for Windows shops.

    Now there's real pricing — and 40% off forever if you get in before May 31st.

    certkit.io/blog/out-of-beta

    #PKI #CertificateManagement

  9. CertKit Agent 1.8: Windows Certificate Store, Java Keystore, and RDP auto-detection.

    We also shipped a retro MS-DOS confirmation dialog on April Fools Day. It is fully keyboard-compatible.

    certkit.io/blog/agent-1.8 #CertificateManagement #PKI

  10. Some organizations have a hard requirement: private keys cannot leave the network perimeter. Third-party cert management has always meant violating that policy.

    The CertKit Local Keystore is the fix. Keys stay on your infrastructure. Full automation still works.

    www.certkit.io/blog/certkit-keystore

    #PKI #CertificateManagement

  11. We found a valid DigiCert certificate on a domain we just purchased, issued to someone we've never met. Getting it revoked took 6 emails. 72 hours after confirmed revocation, every browser still trusts it.

    certkit.io/blog/bygonessl-happ

    #InfoSec #CertificateManagement

  12. You can automate issuance and still ship outages.

    Certificate lifecycle is a loop:

    issue → deploy → verify.

    Most teams stop at “renewal succeeded” and skip the only part users care about, what the endpoint is actually serving.

    certkit.io/blog/issuance-autom
    #ACME #CertificateManagement

  13. Let's Encrypt is moving to 45-day certificates by February 2028, a year before the industry mandate. Everyone focuses on the certificate lifetime, but the real disruption is authorization reuse dropping from 30 days to 7 hours.

    That means nearly every cert request requires fresh validation. Batch operations across a day? Broken. Hardcoded 60-day renewal intervals? Expired certificates.

    certkit.io/blog/45-day-certifi

    #PKI #CertificateManagement

  14. One API key with access to everything is fine until a contractor leaves or a key leaks.

    CertKit now supports multiple applications with scoped API keys. Split your certificates by product, environment, or team. Your marketing site automation never sees production infrastructure. If a key gets compromised, revoke it without affecting everything else.

    All users can create up to 6 applications today.

    certkit.io/blog/application-ma

    #PKI #CertificateManagement

  15. We published the CertKit roadmap and it's interactive. Every feature has a vote button. Tell us what to build next instead of us guessing.

    Current focus: Host Agent for certificate distribution. On deck: SSO, user roles, alerting. Further out: Private CA support and a CT Log API (maybe).

    Feature not listed? Tell us. We've shipped things based on a single request before.

    certkit.io/blog/what-should-we

    #CertificateManagement #PKI

  16. youtube.com/watch?v=fXx29Ml99xM

    SecPoint Protector V65 UTM Firewall – Easily Create Self-Signed Site Certificates

    The SecPoint Protector V65 UTM Firewall now makes it effortless to create secure, self-signed site certificates directly from its intuitive interface.

    ✅ Easy, Fast Certificate Creation
    ✅ Instant SSL/TLS Security
    ✅ Ideal for IT teams and MSPs

    #CyberSecurity #SecPoint #Protector #UTM #CertificateManagement #NetworkSecurity #SSL #TLS #ITsecurity #CyberDefense

  17. 📢 hot off : cert-manager has been approved for CNCF graduation! 🎉
    86% of new production clusters are deployed with cert-manager as standard practice!
    Congrats to Jetstack (now Venafi, CyberArk) and all the maintainers and contributors 👏

    Read the Cloud Native Computing Foundation ( ) announcement for more details:
    cncf.io/announcements/2024/11/

Share on Mastodon

Enter the server where you have an account.