Skip to content
rcrootcerts.com

Manage

Certificate management is an operating capability, not an annual project.

Eight stages run continuously. Each one has signals that prove it works — and an anti-pattern that lets it look healthy while it fails.

  1. Practices

    • Scan externally and internally, then reconcile against Certificate Transparency
    • Query CA accounts, load balancers, cloud services and secret stores directly
    • Treat every discovery run as a diff, not a snapshot

    Signals it works

    • Network scan coverage
    • CT log matches for your domains
    • Unclaimed certificates per month

    Anti-pattern

    A one-off spreadsheet audit that is stale the week it is finished.

    Usually owned by: PKI

Sequencing

If you can only do one thing this quarter

No inventory yet

Do discovery and ownership. Everything downstream is guesswork until certificates have owners.

Inventory exists, renewals are manual

Automate issuance and deployment together. Half-automated renewal is the most common outage cause.

Automation is in place

Rehearse mass replacement and start crypto-agility work. Both are tested only under pressure otherwise.