Skip to main content

IT security

What is the TLS certificate lifecycle?

From CSR and issuance to renewal and revocation: See the 6 phases of the TLS certificate lifecycle, and why shorter lifetimes demand automation.

In short

The TLS certificate lifecycle covers all the phases from ordering and issuance through installation and monitoring to renewal or revocation.

Every TLS certificate has a fixed lifetime, and managing it has become a business-critical discipline: A missed expiry means browsers block your website, API integrations fail, and customers are met with alarming security warnings. The pressure is growing, because the industry, through the CA/Browser Forum, is gradually cutting the maximum certificate lifetime, according to plan towards roughly 47 days by 2029.

That makes manual renewal in spreadsheets effectively untenable for most organisations. The key points are that you need a consolidated overview of all certificates, that monitoring must warn well before expiry, and that renewal should be automated, for example via the ACME protocol.

MI Support IT has many years of specialist experience with PKI and helps Danish businesses take control of the entire certificate lifecycle, from inventory and monitoring to full automation.

Back to the glossary

What is the TLS certificate lifecycle?

The TLS certificate lifecycle is the entire journey from a certificate being ordered until it is renewed or taken out of service. Every digital certificate has a fixed validity period, which is why certificate management is never a one-off task: It is a cycle that repeats for every single certificate in your PKI, from the website through APIs to internal systems. The more certificates and the shorter the lifetimes, the more important it becomes to manage the cycle systematically instead of reacting when something expires.

The 6 phases of the certificate lifecycle

  1. Ordering (CSR): You generate a key pair and a Certificate Signing Request with your details. The private key stays with you.
  2. Issuance: A certificate authority validates your control of the domain and signs the certificate.
  3. Installation: The certificate and any intermediate certificates are installed on web servers, load balancers and gateways.
  4. Monitoring: Expiry dates, chain completeness and protocol configuration are monitored continuously, so problems are caught before users notice them.
  5. Renewal: A new certificate is issued and rolled out well before expiry, preferably automatically.
  6. Revocation: If the private key is compromised, or a system is decommissioned, the certificate is revoked with the CA so it can no longer be misused.

Why are certificate lifetimes getting shorter?

The maximum lifetime of public TLS certificates has been cut several times, from several years to under one year today. Through the CA/Browser Forum, the industry has adopted a plan to gradually reduce the lifetime further towards 2029, where the cap is set to end up around 47 days. The rationale is security: Shorter lifetimes limit the window for misuse of leaked keys and ensure the domain validation is fresh. The consequence for you is tangible: Certificates that previously needed renewing once a year will soon need renewing many times a year. The Danish Centre for Cyber Security generally points to up-to-date and correctly configured encryption as a cornerstone of robust security, and short certificate lifetimes pull in the same direction.

Manual or automated renewal?

Manual renewal works as long as you have few certificates and good discipline: a calendar reminder, an order, an installation. But with a growing number of certificates and falling lifetimes, both the workload and the risk of the missed expiry that takes the website down on a Friday evening keep growing. Automation via the ACME protocol, supported by Let's Encrypt and several commercial CAs among others, removes that risk: Certificates are ordered, validated and deployed automatically without human intervention. Getting there requires an overview first: a consolidated inventory, monitoring of everything with an expiry date and a plan for the systems that cannot be automated yet. We have described that entire journey, including secure key storage in an HSM, in the e-book PKI and HSM in practice.

How MI Support IT can help

We have many years of specialist experience with PKI and certificate lifecycles in Danish businesses: We establish the overview, set up monitoring and automate renewal, so an expiry never becomes an outage. Read more under PKI Management, or contact us for a review of your certificates.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.