Skip to main content
PKI and certificate operations

PKI Management and certificate automation

Expired certificates stop systems without warning. You get design, operations and automation of your PKI, so certificates are renewed in time, even at 47-day lifetimes.

IT-sikkerheds-illustration

Preventing downtime

Avoid major outages. An expired certificate stops systems without warning.

Your PKI infrastructure needs to be effective, secure and up to date. Our consultants review the setup, close the weaknesses and keep it maintained, so certificates never expire unnoticed.

Serverrum med rack-monteret udstyr

One supplier for your entire PKI. Design, security assessment, training, lifecycle, compliance and operations.

You decide how much we take on: a single design project or full operation of the entire infrastructure. This is what we cover:

PKI design and implementation

A PKI solution that fits your needs: from a basic infrastructure to an advanced setup. We design, implement and test that every component works together.

Security assessment and risk management

A detailed review of your current PKI setup finds the weaknesses before they are exploited. Afterwards we can follow up on an ongoing basis, so the infrastructure holds up against new threats.

Training and support

Your own team learns to administer and maintain the PKI system. Afterwards our specialists are on hand with support for everything from daily tasks to complex faults.

Certificate lifecycle management

Certificate management is an ongoing process. We handle the full lifecycle: issuance, renewal, revocation and expiry. Your certificates stay valid, and the risk of security gaps falls.

Compliance

Your PKI infrastructure must meet legal requirements and industry standards. We document that the setup complies with everything from GDPR to specific standards such as GxP and PCI.

Operations

Day-to-day operation of your PKI solution, including operation of Hardware Security Modules (HSM). You avoid keeping specialist knowledge in-house for tasks that only come up a few times a year.

Why companies choose us for PKI. Experience, fixed support and a level you choose yourself.

With PKI advisory from MI Support IT you get:

  • Experience: The consultants have worked with PKI and information security for many years, with both ADCS and Venafi.
  • You choose the level: From advisory on a single project to full operation of the entire certificate infrastructure.
  • Fixed support: You get a named contact person with specialists who know your setup, when something needs changing or fails.
  • Ongoing risk assessment: New threats and new browser requirements are assessed on an ongoing basis, and the setup is adjusted before they hit you.
Gruppe af kollegaer i samarbejde omkring en bærbar

Public certificates

Shorter lifetimes for public TLS certificates. From 398 days to 47 days in 2029, manual renewal will not keep up.

Browser and CA/Browser Forum requirements are tightening over the coming years. The maximum lifetime of public TLS certificates falls in stages towards 2029, when a certificate is valid for just 47 days. That requires automation, processes and visibility, as manual renewal becomes practically impossible. Certificates are typically issued via established issuers such as DigiCert, which browsers and customers already trust.

Timeline for maximum TLS certificate lifetime
Effective fromMaximum lifetime
Today to 14 March 2026398 days
15 March 2026200 days
15 March 2027100 days
15 March 202947 days

Lifecycle management is no longer optional

When a certificate must be renewed every 47 days, issuance, installation, validation and revocation must run automatically. We introduce certificate lifecycle management together with you: discovery of every existing certificate in the environment, automation with ACME and monitoring with alerts. No certificate expires unnoticed.

How we help you

  • Discovery and inventory of all public and internal certificates
  • Automated issuance and renewal via ACME, API and SCEP with integration to your CA
  • Monitoring, alerting and reporting on expiry and compliance
  • Processes and ownership, so responsibility for every certificate is clear
Cloud-infrastruktur-visualisering

Your certificate infrastructure in safe hands. Specialist PKI operations with Microsoft ADCS and Cyberark, formerly Venafi.

PKI management with us specialises in Microsoft Active Directory Certificate Services (ADCS) and Venafi solutions. Your certificates are managed and protected correctly throughout their lifecycle. Automation runs in Cyberark Zero Touch PKI (formerly Venafi) and Cyberark Certificate Manager (formerly Venafi TLS Protect). That combines automatic renewal with strong security.

Active Directory Certificate Services (ADCS)

Microsoft ADCS is a key component in many companies' PKI. Our team designs, implements and administers ADCS solutions, so your setup runs stably and meets your security requirements.

Cyberark Zero Touch PKI (formerly Venafi)

Cyberark Zero Touch PKI (formerly Venafi) fully automates certificate management. Fewer manual processes mean fewer errors, and your certificates are always correctly installed. We set up and operate the solution for you.

Cyberark Certificate Manager (formerly Venafi TLS Protect)

Cyberark Certificate Manager (formerly Venafi TLS Protect) protects your TLS certificates, keeping applications and networks closed to unauthorised access. We administer and secure every TLS certificate in your organisation with the solution.

Secure your company's digital identity. Book a meeting, and we will review your PKI and point out what is urgent.

You get a concrete view of the gap between your certificate infrastructure and the new lifetime requirements, and of what the next step is.