Our organization manages roughly 35 certificates across various servers and services. With public certificate lifetimes potentially reaching 47 days by 2029, manually renewing them the way we do today could become a nearly full-time responsibility. The transition to newer certificate requirements adds another layer of complexity, and renewing certificates 10–20 days early would waste a significant portion of their already-short validity.
What are other IT teams doing to prepare? I know certificate automation tools are becoming more common, but some appear tied to particular vendors or platforms. I'm interested in practical approaches for public-facing services, internal systems, appliances, monitoring, and anything that cannot easily support automated renewal.
5 Answers
Treat this as an automation project now rather than waiting for 47-day certificates to become a crisis. Inventory every certificate, monitor expiration centrally, and move public-facing certificates to ACME wherever possible. The renewal process should run automatically on a schedule that leaves enough time to retry failures before the certificate expires.
For public services, ACME is the usual answer. Tools such as Certbot, win-acme, and other ACME clients can work with multiple certificate authorities, not just one provider. DNS-based validation is especially useful when a service is behind a proxy, firewall, or tunnel. The client can obtain the certificate and run deployment scripts to install it on web servers, load balancers, or appliances.
The difficult part is often not obtaining the certificate but installing it correctly. Nonstandard systems may need a custom script, plugin, or a reverse proxy that handles certificates on their behalf.
The goal of shorter lifetimes is not to create more manual work; it is to make compromised or misissued certificates less useful. The operational answer is lifecycle automation: maintain an accurate inventory, renew well before expiration, alert on failures, and test that the newly issued certificate is actually installed and being served. Once the process is automated, having dozens of certificates should be routine rather than a monthly fire drill.
Make certificate automation a vendor and procurement requirement immediately. For systems that cannot renew directly, investigate putting them behind an ACME-enabled reverse proxy. Anything that still requires manual renewal should be documented, monitored, and placed on a replacement plan—especially obsolete appliances whose vendors have no automation roadmap.
Use an internal CA or an ACME-compatible internal CA for systems that do not need certificates trusted by unmanaged public clients. Internal services can use different policies and longer lifetimes, while user-facing systems should still be automated and closely monitored. Options include an existing enterprise CA, step-ca, or Vault-based PKI, depending on your environment and operational requirements.
Some devices, guest portals, and network access systems still need publicly trusted certificates because they serve unmanaged clients. Those exceptions need to be identified separately rather than assuming every internal hostname can use a private CA.

With a short lifetime, renewing roughly once a month makes sense. That leaves some extra time to troubleshoot a failed validation or deployment instead of being forced into an emergency renewal.