Automation and lifecycle.
WHAT AUTOMATED ISSUANCE PROVIDES
Certificates obtained and renewed without human action.
HOW VALIDATION IS PERFORMED
Serving a token over the web Publishing a record in DNS Completing a challenge over the encrypted connection
WHAT DNS VALIDATION ENABLES
Wildcard certificates, and issuance for names not publicly reachable.
WHY AUTOMATION MATTERS MOST
Validity periods are shortening, and manual renewal is no longer practical.
WHAT CAUSES OUTAGES
Renewal silently failing Certificates deployed to some servers and not others Intermediates not updated The renewal process losing access to validate
WHAT TO MONITOR
Expiry, from outside, checking what is actually served.
WHY FROM OUTSIDE
Checking your own automation only confirms it believes it succeeded.
WHAT TO ALERT ON
Fewer than several weeks remaining.
WHAT TO AUTOMATE BEYOND ISSUANCE
Deployment to every server, and reloading services.
WHAT TO RECORD
Every certificate, where it is deployed, and what issues it.
WHAT TO TEST
The renewal process, before the first expiry.