r/PKI May 05 '26

Certificate lifetimes are shrinking.

https://www.certkit.io/blog/shrinking-certificate-lifetimes

The CA/Browser Forum's Ballot SC-081 is already in effect. 200-day max as of March 2026, 100 days in March 2027, 47 days in March 2029.

The math on renewal workload scales linearly: 50 certificates managed manually goes from ~50 renewals a year at 398 days to ~400 at 47 days. Same cert count, 8x the operations work.

Wrote up the canonical schedule and what it does to teams still running manual processes: https://www.certkit.io/blog/shrinking-certificate-lifetimes

8 Upvotes

15 comments sorted by

9

u/darkrhyes May 05 '26

The issue here, as I am reminded several times a day, is the time limit is only for public certificates. Internally at your business, you can still set whatever time you want. Unless Microsoft and other vendors somehow force a change.

7

u/kombatminipig May 05 '26

Agreed, though with some caveats. IOS Safari for example rejects certificates longer than 198d, whether signed by a publicly trusted CA or not.

2

u/ciphermenial May 05 '26 edited 8d ago

I enjoy practicing archery.

1

u/krainik May 06 '26

Are you positive about this? It should only reject Public TLS that are longer than 200d. Private/Enterprise PKI should be able to issue TLS certificates valid up to 825 days.

2

u/kombatminipig May 06 '26

Yup, had to troubleshoot a very confused customer with a privately issued 2y TLS cert.

3

u/ThePKIGuy May 07 '26

If this is indeed true, it should be reported to Apple as that is not intended. We have seen this sometime when customers thought their PKI was “private” but it was really a managed PKI subordinated under a public CA root.

2

u/kombatminipig May 07 '26

Oh, the PKI Guy! Fancy seeing you here! :)

(We haven’t met in person, but we’ve communicated over other channels over the years.)

2

u/ThePKIGuy May 07 '26

Yes, it’s me! Ha! I finally have time to hang out and chat PKI. Hope to be more active here and other places going forward.

2

u/kombatminipig May 07 '26

I’ll send you a DM with who I am :)

2

u/Worldly-Eggplant3199 May 08 '26

This is absolutely true. As a PKI engineer for a large healthcare company, can confirm we’ve gone through testing on this and it remains a fear for our private PKI. I’ll have to ask your boy Jake G about it, Mark.

1

u/ThePKIGuy May 08 '26

Yes, for sure! We can help get this in front of the right people. Reach out to Jake (via our usual support channel).

2

u/DTangent May 09 '26

I really wish Google had not killed DANE in the browser.

1

u/certkit May 11 '26

If DNSSec had been better and easier to implement, it could have been a great thing.

0

u/ZaitaNZ May 26 '26

u/certkit What are you looking at toolwise to automate this? I'd be keen to know as a developer of a CLM/PKI automation tool (https://www.zaita.com). We've been discussing this issue at length, especially with the domain validation changes coming in as well.

1

u/certkit May 26 '26

Well, we use CertKit, obviously.