Skip to content
Mike Reams
← Diagrams

DGM · IT Standard

TLS Certificate Architecture Standard

A TLS certificate standard keeps one inventory with an owner for every certificate, issues only from approved CAs and automates renewal.

Lifecycle diagram: six stages in a loop (request, approve, issue, deploy, monitor, renew or revoke) around a central certificate inventory that records every certificate's owner, CA and expiry. A note gives the public TLS validity schedule: 200 days since March 2026, 100 in 2027, 47 in 2029.Lifecycle diagram: six stages in a loop (request, approve, issue, deploy, monitor, renew or revoke) around a central certificate inventory that records every certificate's owner, CA and expiry. A note gives the public TLS validity schedule: 200 days since March 2026, 100 in 2027, 47 in 2029.

What it is

A TLS certificate standard turns certificates from files someone installed once into managed assets. It says who may request a certificate, which certificate authorities may issue it, how it is deployed and renewed, and how anyone finds out before it expires. The usual failure it prevents is the outage nobody saw coming: an expired certificate on a system no one knew had one.

The lifecycle

  1. Request. A certificate signing request with a named owner and a stated purpose.
  2. Approve. Policy checks the CA, the key type and the names on the certificate.
  3. Issue. A public CA for internet-facing names, a private CA for internal services.
  4. Deploy. Automated through ACME or an agent wherever the platform allows it.
  5. Monitor. Expiry, key strength, and discovery scans for certificates the inventory does not know about.
  6. Renew or revoke. Renew well before expiry; revoke and replace at once when a key or CA is compromised.

What the standard should decide

  • Approved CAs, and which kinds of names each one may issue.
  • A key and algorithm baseline, kept in one place and aligned with NIST key-management guidance, not hard-coded in each application.
  • Ownership: every certificate belongs to a named person and a service. An ownerless certificate is an incident waiting for a date.
  • Automation as the default. Manual renewal is an exception with a reason and an end date.
  • Response: how fast the estate can replace certificates when a CA or algorithm stops being trusted.

Why it matters now

Public TLS certificates are getting shorter lives. Under CA/Browser Forum ballot SC-081 the maximum validity fell to 200 days in March 2026, falls to 100 days in March 2027 and to 47 days in March 2029. Renewing by calendar reminder does not survive that schedule; an inventory and automation do.

Based on NIST SP 1800-16, TLS Server Certificate Management; NIST SP 800-57 Part 1 Rev. 5, Recommendation for Key Management; CA/Browser Forum ballot SC-081v3. Drawn for this site; no client or employer material.